CONTROL A · SAFEExact read-only diagnostic
No safe execution recorded in this session.

GPT-5.6 reads the real checkout demo repository and emits a genuine shell tool call. AgentGuard catches that exact model-generated command before execution, then turns it into a durable regression.
Results appear only after a live model request completes.
No safe execution recorded in this session.
No intercepted attack recorded in this session.
Capture the proposed operation and exact payload.
Evaluate identity, destination, data, and policy.
Allow, redact, require approval, or stop execution.
Keep durable evidence for replay and regression.