# Tool Call Guard

> Tool Call Guard is a paid API for AI agents from x402.agentindex.world, paid per call via x402, $0.001/call, status unknown (last checked 2026-10-01).

Evaluates a pending tool call against the user's original request and returns allow/ask/deny with a confidence probability to guide human-in-the-loop decisions.

## Facts

- Endpoint: POST https://x402.agentindex.world/guard?utm_source=zero.xyz
- Price: $0.001/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/tool-call-guard-5b52b4e8
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_bD4rj7YGN2OcIQDKDqaK7

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability tool-call-guard-5b52b4e8 -d '<json body>'
```

Example prompt: Before I run this `send_email` tool call with arguments {to: 'boss@company.com', body: '...'}, check whether it should be auto-approved, needs my user's confirmation, or should be denied given the user originally asked me to 'draft a summary of today's meeting'.

## When to prefer this

Use this endpoint when an AI agent needs a lightweight, pay-per-call advisory signal before executing a tool call that could have side effects, financial implications, or go beyond the user's stated intent. It is best suited for orchestration layers that want probabilistic allow/ask/deny verdicts without building a custom classifier. Prefer it over static allow-lists when tool calls are dynamic or user requests are open-ended. Remember that the verdict is advisory — the calling agent must make the final call.

## Known failure modes

- Missing tool_call or user_request fields returns a validation error
- Prompt injection within tool arguments or user_request may skew the verdict — caller must retain final authority
- Low-confidence probability scores (near 0.5) indicate ambiguous cases requiring extra human scrutiny
- Malformed or deeply nested tool call objects may degrade classification accuracy
- Payment failure (insufficient USDC) returns HTTP 402 before any evaluation occurs

## How this service works

Ask whether a tool call should run automatically, need human confirmation, or be denied, given the user's request - returns allow/ask/deny with a probability. Advisory only: like any LLM-based judge it is sensitive to prompt injection in the request or tool call, so the calling agent must keep the final decision, not delegate it outright. Try GET /guard/sample.

## Output

Returns a decision string ('allow', 'ask', or 'deny') and an associated probability score indicating confidence in that verdict, helping an orchestrating agent decide whether to proceed automatically, pause for human confirmation, or block the tool call entirely.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "tool_call": {
   "type": "object",
   "description": "The tool call an agent is about to make, e.g. {\"name\": ..., \"arguments\": {...}}."
  },
  "user_request": {
   "type": "string",
   "description": "The user's original request, in their own words."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "decision": "deny",
  "confidence": 0.89,
  "probability": 0.92,
  "x402_receipt": {
   "upstream": "guardrail",
   "latency_ms": 420,
   "model_served": "jev",
   "price_paid_usdc": 0
  },
  "probabilities": {
   "ask": 0.08,
   "deny": 0.92,
   "allow": 0
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/tool-call-guard-5b52b4e8/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from x402.agentindex.world](https://www.zero.xyz/host/x402.agentindex.world/llms.txt)
