Scan an agent tool invocation before executing it
Regex-only — sub-millisecond. Detects: shell injection
(shell.dangerous), destructive SQL (sql.dangerous), SSRF to
cloud metadata (ssrf.imds) or private networks
(ssrf.private_network), disallowed schemes (ssrf.scheme),
path traversal (path.traversal), sensitive paths
(path.sensitive), denylist hits (tool.denied), oversized
arguments (tool.args_too_large), plus PII in argument strings.
Authorizations
Antidote workspace API key (ak_live_…). Use this header for the
scan API and the OpenAI proxy routes. The required permission
scope is runtime_security.scan for scan endpoints,
runtime_security.view for read-only analytics, and
runtime_security.manage for configuration changes.
Body
Response
Verdict + reasons
allow, redact, block Original arguments with PII string leaves masked.
JSON-serialised size of the arguments.

