{"uid":"cap_bD4rj7YGN2OcIQDKDqaK7","slug":"tool-call-guard-5b52b4e8","name":"Tool Call Guard","description":"Ask whether a tool call should run automatically, need human confirmation, or be denied, given the user's request - returns allow/ask/deny with a probability. Advisory only: like any LLM-based judge it is sensitive to prompt injection in the request or tool call, so the calling agent must keep the final decision, not delegate it outright. Try GET /guard/sample.","url":"https://x402.agentindex.world/guard?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"tool_call":{"type":"object","description":"The tool call an agent is about to make, e.g. {\"name\": ..., \"arguments\": {...}}."},"user_request":{"type":"string","description":"The user's original request, in their own words."}}},"responseSchema":{"type":"json","example":{"decision":"deny","confidence":0.89,"probability":0.92,"x402_receipt":{"upstream":"guardrail","latency_ms":420,"model_served":"jev","price_paid_usdc":0},"probabilities":{"ask":0.08,"deny":0.92,"allow":0}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_VxgXef0gIRRI61W6QOuec","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Evaluates a pending tool call against the user's original request and returns allow/ask/deny with a confidence probability to guide human-in-the-loop decisions.","exampleAgentPrompt":"Before I run this `send_email` tool call with arguments {to: 'boss@company.com', body: '...'}, check whether it should be auto-approved, needs my user's confirmation, or should be denied given the user originally asked me to 'draft a summary of today's meeting'.","exampleUseCases":[{"title":"Auto-approval gate for file writes","prompt":"I'm about to call `write_file` with path '/etc/hosts' and some content — before I do it automatically, check whether that should be allowed, flagged for my user to confirm, or outright denied given they asked me to 'update my hosts file to block ads'."},{"title":"Catching scope-creep in a shopping agent","prompt":"My agent is about to call `place_order` for $349 worth of items, but the user only asked to 'browse laptops under $300' — can you tell me if this tool call should run automatically, needs confirmation, or should be blocked?"},{"title":"Human-in-the-loop for sensitive API calls","prompt":"Before my agent fires `delete_repo` with repo name 'my-prod-app', check if that action should be auto-allowed, require human sign-off, or be denied — the original user request was 'clean up my old test repositories'."}],"resultDescription":"Returns a decision string ('allow', 'ask', or 'deny') and an associated probability score indicating confidence in that verdict, helping an orchestrating agent decide whether to proceed automatically, pause for human confirmation, or block the tool call entirely.","failureModes":["Missing tool_call or user_request fields returns a validation error","Prompt injection within tool arguments or user_request may skew the verdict — caller must retain final authority","Low-confidence probability scores (near 0.5) indicate ambiguous cases requiring extra human scrutiny","Malformed or deeply nested tool call objects may degrade classification accuracy","Payment failure (insufficient USDC) returns HTTP 402 before any evaluation occurs"],"whenToPreferThis":"Use this endpoint when an AI agent needs a lightweight, pay-per-call advisory signal before executing a tool call that could have side effects, financial implications, or go beyond the user's stated intent. It is best suited for orchestration layers that want probabilistic allow/ask/deny verdicts without building a custom classifier. Prefer it over static allow-lists when tool calls are dynamic or user requests are open-ended. Remember that the verdict is advisory — the calling agent must make the final call.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:41:32.978Z","isFirstParty":false,"canonicalSlug":"tool-call-guard-5b52b4e8"}