# Agent Watchdog

- **Event:** [Llama Lounge Agentic Hackathon](https://cerebralvalley.ai/e/llama-lounge-agentic-hackathon)
- **When:** Feb 27 at 9:00 AM – Feb 28 at 10:00 PM (PST)
- **Where:** 135 Constitution Dr, 8th floor, Menlo Park
- **Team:** [Yusuke Muraoka](https://cerebralvalley.ai/u/notsofat), [Isabella kang](https://cerebralvalley.ai/u/kang_dev)
- **GitHub:** https://github.com/not-so-fat/agent_watchdog
- **Demo video:** https://youtu.be/e3Y2_oifxcU
- **Gallery:** https://cerebralvalley.ai/e/llama-lounge-agentic-hackathon/hackathon/gallery
- **Page:** https://cerebralvalley.ai/e/llama-lounge-agentic-hackathon/hackathon/gallery/2

AI agents like Cursor, Claude, and Copilot now run shell commands, read files, and even make payments through agentic wallets. They have real-world power without a permission system. A prompt injection or buggy plugin can leak API keys, run dangerous CLI commands, or spend money without the owner’s knowledge. Today the only defense is “don’t give agents access,” which blocks real productivity gains.

We built Agent Watchdog to solve this. It uses system-level process monitoring to block risky actions by default, lets owners grant scoped access with passkey authentication for specific tasks, budgets, and time limits, and provides a dashboard to audit every action and payment. Agents stay autonomous within scope, but the owner always keeps control.

---

Markdown version of https://cerebralvalley.ai/e/llama-lounge-agentic-hackathon/hackathon/gallery/2. Site index for agents: https://cerebralvalley.ai/llms.txt · full text: https://cerebralvalley.ai/llms-full.txt
