Agentmetry
A local-first flight recorder for AI coding agents.
Agentmetry hooks the tool lifecycle of Claude Code, Cursor, Codex and Antigravity, writes every tool call, approval and denial to a hash-chained JSONL trail on your machine, and runs sequence detection over the session. A credential read followed by network egress becomes one finding rather than two unremarkable log lines.
Everything runs locally. There are no cloud calls and no telemetry. Forwarding to Elastic ECS, Splunk HEC or a webhook exists and is off unless you configure it.
pip install agentmetry
agentmetry doctor
Check the detection claims yourself
The corpus ships inside the package, so this works from a clean install:
agentmetry benchmark
It replays recorded sessions through the real rule engine and exits non-zero on any missed rule or any false positive. The benign half is the number that matters: any tool can fire on an attack, and a feed that cries wolf gets muted.
What it does not do
- It is not a CASB. It records the agents you wire in. An unmanaged browser assistant is invisible to it.
- It is a recorder, not a sandbox. The only enforcement path is pre-execution DLP blocking in the hook.
- The DLP is regex, not ML. A starting pack you extend in YAML.
- It is a public alpha. Integration surfaces may still change.
Full documentation, the event schema, and the SIEM integration guides are in the repository.
- Source and issues: https://github.com/blitzcrieg1/agentmetry
- Website: https://agentmetry.ai
Apache-2.0.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file agentmetry-0.4.0.tar.gz.
File metadata
- Download URL: agentmetry-0.4.0.tar.gz
- Upload date:
- Size: 287.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ba04897f9c74ec93ad690e9345bf2eda23aa879672728b8f4e383c1fee1e4a7d
|
|
| MD5 |
c43fd235b09dc47761dce36a433f7425
|
|
| BLAKE2b-256 |
2e944471caafe7a4a2bf15cc66fbddd889b8b25d18eae421187a3aa8bf106766
|
Provenance
The following attestation bundles were made for agentmetry-0.4.0.tar.gz:
Publisher:
release.yml on blitzcrieg1/agentmetry
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agentmetry-0.4.0.tar.gz -
Subject digest:
ba04897f9c74ec93ad690e9345bf2eda23aa879672728b8f4e383c1fee1e4a7d - Sigstore transparency entry: 2371051074
- Sigstore integration time:
-
Permalink:
blitzcrieg1/agentmetry@54e6549e4d995337619e5f06ab8e6346744a89f1 -
Branch / Tag:
refs/tags/v0.4.0 - Owner: https://github.com/blitzcrieg1
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@54e6549e4d995337619e5f06ab8e6346744a89f1 -
Trigger Event:
push
-
Statement type:
File details
Details for the file agentmetry-0.4.0-py3-none-any.whl.
File metadata
- Download URL: agentmetry-0.4.0-py3-none-any.whl
- Upload date:
- Size: 251.0 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1facbaa46a40825106bd848f9d35afd39db40a48bdd9e8973a0a8156e0de078c
|
|
| MD5 |
3a4edc17d8381d591d502adb3443c2b7
|
|
| BLAKE2b-256 |
17eba717012a5e36b8815a232687387d61916b6cafea7e6c4822156523ca6d14
|
Provenance
The following attestation bundles were made for agentmetry-0.4.0-py3-none-any.whl:
Publisher:
release.yml on blitzcrieg1/agentmetry
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agentmetry-0.4.0-py3-none-any.whl -
Subject digest:
1facbaa46a40825106bd848f9d35afd39db40a48bdd9e8973a0a8156e0de078c - Sigstore transparency entry: 2371051093
- Sigstore integration time:
-
Permalink:
blitzcrieg1/agentmetry@54e6549e4d995337619e5f06ab8e6346744a89f1 -
Branch / Tag:
refs/tags/v0.4.0 - Owner: https://github.com/blitzcrieg1
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@54e6549e4d995337619e5f06ab8e6346744a89f1 -
Trigger Event:
push
-
Statement type: