Security1 publisher2 min readPublished
Bitdefender's AI Guardian beta checks coding agents' actions on macOS before they run
Bitdefender's free AI Guardian beta vets each Claude Code and OpenClaw action on macOS, citing tests that manipulated agents in over a third of cases. That rate is Bitdefender's own, so the case for checking every agent action rests on the company offering the check.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- AI Guardian runs in the background and compares each request an agent makes with rules the user defines.
- Each action ends up allowed, flagged or blocked, and every one of those decisions is written to a log kept for auditing.
- Bitdefender says the tool is aimed at malicious instructions that push an agent into unauthorized operations such as reading credentials or system files.
- Bitdefender plans to bring AI Guardian to other operating systems after the macOS beta.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost The beta costs nothing, but someone on the team has to write and maintain the rules that decide which files and commands an agent may touch.
- constraint Fleets with agents on Windows or Linux cannot put the same per-action gate in front of every agent until Bitdefender ships other versions.
- decision Mac teams running Claude Code or OpenClaw can trial a per-action gate now, accepting beta software in the path of every action their agents take.
Agents are being given more access to sensitive data and tools, according to the brief [8]. An attacker who can get malicious instructions in front of one gets the agent's access along with it [5][8]. AI Guardian sits at the point of execution. It judges what the agent has asked to do before anything runs [2].
The over-a-third figure comes from Bitdefender's own research [11]. The public is getting it second-hand, through SC World's summary of a Tech Radar report [9]. Taken on its own terms, it shows that agents can be steered under test conditions Bitdefender chose [11]. The brief does not say how many scenarios the company ran, what counted as a successful manipulation, or whether any of these attacks have been seen outside a test.
For a responder, the audit log is the most useful part of the design [4]. When an agent on a developer's Mac does something it should not have, the first two questions are what it asked to do and what was allowed through. A log of every allow, flag and block decision answers both [4].
Bitdefender argues that agents now act as extensions of their users, so the agents themselves need securing [6]. For now the product behind that argument is a beta that covers initial versions of Claude Code and OpenClaw [3]. It is free while the beta lasts [7].
What to watch
- Bitdefender publishing the test design behind its over-a-third manipulation rate, including scenario count and what counted as success.
- Windows or Linux builds of AI Guardian, or support for agents beyond the initial Claude Code and OpenClaw versions.
- The price Bitdefender sets when the free beta ends.