Resources · Claude connector

Claude GoPlus AgentGuard connectorWhat Claude can do with GoPlus AgentGuard on your machine.

The Claude GoPlus AgentGuard connector exposes 7 tools. 5 read or evaluate without changing anything, 2 change your local trust registry, 0 are undocumented. Here: what Claude can check before you trust a skill, and what this connector does not block.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

What the Claude GoPlus AgentGuard connector changes for agent security

Before you hand an agent a new skill, or let it run a command or sign a transaction, you want a second opinion. This connector, a desktop extension that runs on your own machine, lets Claude ask GoPlus AgentGuard for one: scan a skill folder for risky content, check a trust registry, weigh a proposed action against policy, or simulate a Web3 transaction before anyone signs it.

A skill checked before it is trusted. A developer downloads a community skill and asks Claude whether it is safe. skill_scanner_scan scans the skill directory for malicious or risky content, and registry_lookup shows whether that skill is already in the trust registry.

A verdict on a risky step. An agent wants to run something that looks destructive. action_scanner_decide evaluates the proposed action against policy and returns allow or deny, which Claude can explain in plain words.

A transaction tested, not signed. A crypto user is about to approve a token swap. action_scanner_simulate_web3 simulates it to surface risks before signing.

What it does not do: GoPlus itself says live action blocking goes through its own hooks, and that this connector is best for scans that an agent requests, registry operations and Web3 simulation. In other words, calling a tool from the conversation does not stand guard over everything else running on your machine. The registry is local, so an attestation stays on that computer. And nothing runs on its own schedule: Claude calls these tools while it answers you. If you need recurring checks, look at an automation tool, a different job described on the Integrations hub.

Vocabulary

The vocabulary in one minute

Five words you will see while adding AgentGuard.

Connector
The link you set up once between Claude and another service or program, so Claude can use it while it answers you.
Tool
One named action a connector gives Claude. Claude decides which ones to call; the directory lists each one under its exact name.
Authorization
The screen where you grant the access Claude will use, when the service shows one. Granted once per person, and it can be withdrawn.
Approval
The confirmation Claude waits for before it goes ahead with something that changes data, shown in the conversation at that moment.
MCP
The shared standard connectors are built on: it lets an assistant like Claude talk to an outside service or a program on your computer.
Connect

Add GoPlus AgentGuard to Claude in three steps

  1. 01

    Open Claude Desktop

    AgentGuard is a desktop extension, so it lives in Claude Desktop. Open its settings, go to Customize then Connectors, and find GoPlus AgentGuard. On a Team or Enterprise workspace, an Owner or Primary Owner has to enable it before members can use it.

  2. 02

    Install and enable it

    Start the setup from its row. The publisher documents no extra step for Claude Desktop beyond its requirements, so what you see on screen comes from Claude Desktop itself. If the setup breaks later, Disconnect it and add it again.

  3. 03

    Read what you allow

    If a permission or authorization screen appears, read it before you accept. It belongs to the service, not to Claude, and it sets how far the access goes.

Tools

The 7 tools, sorted by what they do

GoPlus AgentGuard gives Claude 7 tools: 5 that read your account, 2 that change something in it.

Five tools inspect or evaluate, two change the local trust registry. Names stay exactly as Claude shows them.

  • 5 read
  • 2 write

What Claude checks (5)

5 tools

Five tools that scan, look up, list, evaluate or simulate without changing anything.

skill_scanner_scan

Inspects an agent skill directory for malicious or risky content and reports what it finds, so Claude can tell you whether a skill looks safe before you rely on it.

When it helps
you cloned a skill from a public repository and want it checked before your agent loads it.

Sourcegithub.com · October 1, 2026 ↗

registry_lookup

Checks whether a given skill or package is recorded in the trust registry, and what the registry says about it. The lookup only reads; the registry stays as it was.

When it helps
a teammate claims a package was already vetted and you want to confirm it.

Sourcegithub.com · October 1, 2026 ↗

registry_list

Returns every entry in the local trust registry, giving Claude the full picture of what has been marked as trusted on this machine. Reading the list leaves every entry as it was.

When it helps
you want an overview of every skill your setup currently trusts.

Sourcegithub.com · October 1, 2026 ↗

action_scanner_decide

Evaluates a proposed runtime action against policy and returns allow or deny. Claude reads the verdict back to you instead of guessing whether a step is dangerous.

When it helps
an agent suggests a shell command that looks destructive and you want a policy check first.

Sourcegithub.com · October 1, 2026 ↗

action_scanner_simulate_web3

Runs a Web3 transaction in simulation to surface its risks before signing, so nothing reaches the chain while Claude explains the outcome.

When it helps
a wallet asks you to approve an unfamiliar contract and you want to see what it would do.

Sourcegithub.com · October 1, 2026 ↗

What Claude changes (2)

2 tools

Two tools that add or remove trust in the local registry. No source describes a confirmation specific to either, so the general rule below applies.

registry_attest

Approval: see the rule

Marks a skill or package as trusted in the local registry.

What Claude asks for
no source describes a confirmation for this tool, so the general approval rule applies.
When it helps
after a clean scan and your own review, you record that the skill is approved.

Sourcegithub.com · October 1, 2026 ↗

registry_revoke

Approval: see the rule

Withdraws a previous attestation from the registry, so a skill that was trusted no longer is.

What Claude asks for
the publisher documents no confirmation here, so the default rule described below is the one that covers it.
When it helps
a security advisory names a package you trusted last month and you want it pulled at once.

Sourcegithub.com · October 1, 2026 ↗

Approvals

What Claude asks before it acts

By default, Claude stops and asks for your go-ahead before any action it would carry out for you. That covers attesting and revoking here, since no source sets a different rule for those two tools.

On Team and Enterprise, workspace owners decide whether members may let some actions through without a fresh confirmation, and they can limit what a connector may do for the whole organization; nobody overrides that from a personal account. Claude works with the rights of the person using it and nothing more. Here the extension runs locally, and the registry it changes is the one on that machine, not a shared one.

Plans

Which plans it is available on

None of the 819 sheets in the official directory shows plan availability. Connector by connector, that answer is published nowhere: a real gap in the catalogue.

The general rule is published: remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, while desktop extensions like this one install in Claude Desktop. On Team and Enterprise, an Owner or Primary Owner enables a connector for the organization before members use it. For the current status, check the GoPlus AgentGuard sheet in the official directory.

Limits

Where the Claude GoPlus AgentGuard connector stops

A connector is not an automation. Claude calls these tools while it answers you; no scan starts on its own when a new skill lands on your disk.

Only GoPlus documents this connector, in its own repository; Claude's help center has no article on it. A list of tools is an observed floor, not a promise, since an administrator can open actions that appear on no public sheet, and the partner badge is not a security audit: Anthropic says on every sheet that it neither chooses the tools a publisher exposes nor guarantees how they behave. Connect a security tool only if you trust its publisher.

Need help

Need help connecting GoPlus AgentGuard to Claude?

A person reads every message.

FAQ

Questions about the Claude GoPlus AgentGuard connector

01What can Claude do with the GoPlus AgentGuard connector?
Claude can check an agent skill folder for anything malicious or risky, look up or list entries in the local trust registry, weigh a proposed runtime action against policy, and run a Web3 transaction in simulation before anyone signs. It can also attest a skill as trusted or revoke an earlier attestation. You ask in plain words, for example whether a skill you just downloaded is safe, and Claude picks the tool and explains the result.
02Can Claude change anything with AgentGuard?
Yes, two of the seven tools change the local trust registry: one attests a skill or package as trusted, the other revokes an earlier attestation. The other five scan, look up, list, evaluate or simulate without changing anything. A simulated Web3 transaction is not sent, and an allow or deny verdict does not by itself block an action. Signing a transaction or running a command stays outside what these tools do.
03Does Claude ask before it attests or revokes a skill?
By default, Claude asks for confirmation before any action it would carry out for you, and no source describes a confirmation specific to registry_attest or registry_revoke, so that default rule is what applies. On Team and Enterprise workspaces, owners decide whether members can let some actions through without being asked, and they can restrict what the connector may do across the organization, for instance keeping checks open and closing changes.
04Which Claude plans is GoPlus AgentGuard available on?
No official source publishes plan availability connector by connector, and none of the directory sheets shows it. The general rule says remote connectors are open to all users on Claude, Cowork, Claude Desktop and mobile, that desktop extensions install in Claude Desktop, and that on Team and Enterprise an Owner or Primary Owner enables them first. The connector's sheet in the official directory is the only place showing its current status.
05Does AgentGuard through Claude protect everything my agents do?
Not on its own. GoPlus says that for live action blocking you should prefer its own protection hooks, and that this connector is best for scans an agent asks for, trust registry operations and Web3 simulation. When Claude calls action_scanner_decide, it gets an allow or deny verdict on that one action, and nothing more happens unless you act on it. Continuous guarding of everything that runs on your machine is a separate setup described by GoPlus.
06Why doesn't GoPlus AgentGuard appear in Claude on the web?
Because it is a desktop extension. The directory lists Claude Desktop as the only place it works, and the publisher's manifest declares Claude Desktop 0.10.0 or later, plus the Node.js runtime 18 or later, on macOS, Linux and Windows. If you use Claude in a browser or on a phone, the tools will not be available there. On a Team or Enterprise workspace, an Owner or Primary Owner also has to enable it before members can use it.
07Should I use Claude or an automation tool for agent security checks?
They do different jobs, so this is not a ranking. Claude with AgentGuard suits checks you want explained in a conversation: is this skill safe, would this transaction be risky, should this command go through. An automation tool suits checks that must run on a schedule or after an event without anyone asking. The connector never fires by itself, so recurring patrols belong on the automation side or in GoPlus's own tooling.