Summary is AI-generated, newsdesk-reviewed
  • Permiso releases SandyClaw for AI agent skill security with dynamic analysis capabilities.
  • SandyClaw detects malicious AI skills by executing behaviors in a sandbox environment.
  • It uses multiple detection engines and offers cross-framework support for comprehensive security.

Permiso Security has unveiled SandyClaw, a pioneering dynamic analysis platform designed for the security of AI agent skills.

Distinguished as the first of its kind, SandyClaw provides a sandboxed environment where skills are executed, capturing every action both at the large language model (LLM) and operating system levels. This analysis delivers verdicts supported by various detection engines. Customers using the Permiso platform will have unlimited access to this innovative solution.

Addressing Malicious Skills

AI agents rely on skills, which are downloadable capabilities necessary for interacting with tools, APIs, and services. Skill marketplaces have emerged as the primary software supply chain for these agents; however, they are increasingly targets for malicious skills publication. Traditional methods of securing these skills rely on either static code analysis or LLM-based evaluations, both of which fall short by not executing the skills, missing runtime behaviors.

Permiso's threat research team was one of the first to identify and document these malicious skills. Their research contributed to the development of SandyClaw.

Sandbox Detonation Methodology

SandyClaw is compatible with major agent frameworks such as OpenClaw, Cursor, and Codex

The SandyClaw platform utilizes sandbox detonation, a method familiar to cybersecurity experts when evaluating suspicious executables, now applied to AI agent skills. It meticulously records every LLM action, network call, domain resolution, file write, and environment variable access attempt. 

The platform intercepts and decrypts SSL traffic, analyzing it with Sigma, Yara, Nova, and Snort engines complemented by custom detection rules from Permiso. SandyClaw is compatible with major agent frameworks such as OpenClaw, Cursor, and Codex.

Multi-Engine Detection

According to Paul Nguyen, Co-Founder and Co-CEO of Permiso Security, "Agents are only as trustworthy as the skills they run. As skill marketplaces become the primary distribution channel for agent capabilities, the ability to validate what a skill actually does before it reaches your environment becomes a security requirement, not a nice-to-have. That is what SandyClaw delivers."

Critical Capabilities

  • Dynamic detonation with comprehensive behavioral recording at the LLM and OS levels, capturing network calls, file writes, and environment variable accesses.
  • Multi-engine detection with Sigma, Yara, Nova, and Snort supported by Permiso detection rules, providing evidence-based verdicts.
  • Full SSL intercept for decrypted outbound traffic visibility, revealing potential exfiltration attempts.
  • Transparency in verdicts with detailed behavioral records, enabling security teams to verify findings independently.
  • Support and integration across multiple agent frameworks, automatically analyzing skills upon detection of download or installation by the Permiso platform.

Emphasis on Runtime Behavior

Ian Ahl, CTO of Permiso Security, elaborated, "Most skill scanners inspect code or ask an LLM for an opinion. But real risk shows up at runtime: network activity, file writes, and access to sensitive environment variables. SandyClaw was built on the belief that behavior is more revealing than source code alone. We detonate the skill, capture everything it does, and let the evidence speak for itself."

Permiso platform users can now access SandyClaw, which is available immediately. Security teams interested in integrating this solution into their operations can start by registering at sandyclaw.permiso.io.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...