AGENT DETECTION & RESPONSE — ON THE WIRE

Safe AI, everywhere it
runs.

CheckedAgent is the Agent Detection & Response layer for the MCP wire. It sits inline between your agents and every tool they call — inspecting each request and each response through a multi-tier detection pipeline, and blocking malicious traffic before it reaches the tool, or your agent.

Prevention-first. MCP-native. Zero code changes.

Every request and every response inspected before it reaches the model or the tool. No code changes. Drop-in sidecar.

What is Agent Detection & Response?

Agent Detection & Response (ADR) is the security layer that monitors what AI agents actually do at runtime — and intervenes. Endpoint tools see the process; they don't see what the agent was instructed to do, or what a tool's response is about to make it do. ADR fills that gap.

CheckedAgent is ADR at the wire layer: an inline proxy on the MCP protocol itself, inspecting both directions of every tool conversation. Not installed in the agent. Not bolted onto the model. On the wire — where the attack travels.

Not a SIEM rule firing after the fact.

Not an LLM judge bolted onto your agent.

Not a checklist of prompt patterns from last quarter.

Not detection that opens a ticket after the data has left.

CheckedAgent is the protocol layer your agents already speak — instrumented, governed, and auditable.

— 01

Detect. In both directions.

Every request and every response is screened by a multi-tier pipeline — deterministic patterns, obfuscation analysis, semantic signals, and a purpose-built small language model. Other defences inspect what the user typed. The real attack surface is what the tool returns. CheckedAgent reads both.

— 02

Enforce. Before it lands.

Detection without enforcement is a dashboard. CheckedAgent issues inline verdicts — allow, quarantine, block — enforced on the wire before the request reaches the tool, or the response reaches your agent. The verdict is the enforcement. Prevention, at the moment of execution.

— 03

Prove. Every verdict, evidenced.

Each verdict carries its evidence chain: the request, the response, the content that triggered it — correlated and recorded in a tamper-evident audit journal. When your auditor asks what exactly happened, the answer already exists.

Three conditions.
One attack surface.

Autonomous AI agents are being deployed at speed across the enterprise. Combined, three default conditions create an attack surface that no existing security tool addresses.

Access to sensitive data.

Agents reading emails, querying databases, accessing financial records, customer data, patient records. The data is real. The exposure is real.

CONDITION_01

Exposure to untrusted content.

Web pages, documents, user inputs — any of which can contain hidden instructions designed to hijack the agent's behaviour. Prompt injection is the attack vector.

CONDITION_02

Ability to communicate externally.

Send emails, make API calls, write files, post to Slack. Once an agent is compromised, it has the keys to act — and the blast radius is the entire organisation.

CONDITION_03
Any one alone is manageable. All three together — the default configuration of most enterprise AI agents — is CheckedAgent's core problem statement.

Why now.

Three categories of agent attack — prompt injection, indirect injection, and tool-output social engineering — have moved from theory to demonstrated, reproducible attacks against production-style systems in the last year. The window for requiring this capability is the window before regulators are asking for it.

80%1
of Fortune 500 are deploying AI agents this year
47%2
have GenAI controls
Dec 2, 2027
High-risk obligations (EU AI Act Art. 12 / Reg (EU) 2024/1689) — deferred from Aug 2026 under the Digital Omnibus.
The deadline moved, not the requirement.
  1. 1Microsoft, Cyber Pulse: AI Security Report (Feb 2026). First-party telemetry, Nov 2025: 80%+ of Fortune 500 are running AI agents in production. microsoft.com/security-insider
  2. 2Microsoft, Cyber Pulse: AI Security Report (Feb 2026). 47% of organisations have implemented GenAI-specific security controls — a 53% controls gap. microsoft.com/security-insider

Your agents are already on the wire. The only question is whether you can see what they're saying.

CheckedAgent ships as a sidecar gateway. Deployment is hours, not weeks. Pilot with one agent, one tool surface, one tenant — measure detection on traffic you already have.

Book a 30-minute architecture review

Where CheckedAgent fits

CheckedAgent is the inspection layer on the wire between your agents and the MCP tools they call. It runs inline as a proxy, sidecar or as a desktop application protecting the entire attack surface — wherever your agents are built and hosted — and inspects every tool request and every tool response. It adds runtime MCP inspection to the platforms you already run; it does not replace them.

PlatformWhat it securesWhat CheckedAgent adds on the wire
AWS Bedrock & AgentCoreModel inputs and outputs via Bedrock Guardrails, plus agent hosting and runtime via AgentCore.Inline inspection of the MCP tool calls and responses themselves — request and response — with no agent code changes. Cloud-agnostic, so the same control applies outside the Bedrock ecosystem.
Microsoft Agent FrameworkIn-process agent orchestration and governance policy, running inside the agent's own process.Out-of-process inspection on the wire, in a separate trust boundary from the agent, covering MCP tool responses as well as requests.
Salesforce AgentforceAgents, actions and data inside the Salesforce ecosystem.Protocol-level inspection of MCP traffic to any external tool or server the agent reaches, independent of the platform.
Google Gemini Enterprise & ADKModel-layer safety and the agent development and runtime environment.Bidirectional MCP traffic inspection on the wire — model-agnostic and cloud-agnostic.
Any MCP client (Claude, ChatGPT, custom)The agent itself and its model provider.A single inspection point for every MCP server those clients connect to — every request and every response, correlated.

Comparing approaches, not just platforms? See how the five MCP-security approaches compare →

Common questions

What is Agent Detection and Response (ADR)?

Agent Detection & Response is runtime security for AI agents: monitoring what agents do as they act, detecting malicious or anomalous behaviour, and intervening before damage is done. Endpoint and network tools cannot see agent intent or tool-response content. ADR operates at the layer where agents reason, call tools, and receive instructions.

How is wire-layer ADR different from prompt firewalls and client-side agent monitoring?

Prompt firewalls inspect what the user sends to the model — one direction, one surface. Client-side monitors run inside the agent's execution loop and must be adopted by every agent individually. Wire-layer ADR inspects the protocol between agents and tools: both directions, every agent, any framework — with no changes to agent code. The response path, where injected instructions actually arrive, is covered by design.

How do you secure MCP tools on AWS Bedrock AgentCore?

Bedrock Guardrails inspect model inputs and outputs, and AgentCore hosts the agent. CheckedAgent runs inline as a sidecar on the connection between the agent and its MCP tools, inspecting every tool request and every tool response. It needs no agent code changes and is cloud-agnostic, so the same inspection applies whether or not the agent runs on AWS.

Does CheckedAgent inspect MCP tool responses, not just requests?

Yes. CheckedAgent inspects both directions of MCP traffic — the request the agent sends to a tool and the response the tool sends back — and correlates them by JSON-RPC id. Inspecting responses matters because a compromised or manipulated tool can return harmful content even when the request looked legitimate.

Can CheckedAgent run with any agent framework?

Yes. CheckedAgent is MCP-native and sits at the protocol layer, so it works with agents built on Microsoft Agent Framework, Salesforce Agentforce, Google ADK, the major MCP clients, or a custom stack. Because it runs as an inline sidecar, it requires no changes to agent code.

— Request a demo

Every Agent action.
Checked.

30 minutes with the team building it. Not a sales rep. We'll show the full pipeline, run your suspected attack patterns through it, and answer the questions your auditor is already asking.