Hardening checklist
The Credential & exposure hardening checklist is at the bottom of Agent Guardrails → Settings (the dashboard’s Hardening card links to it). The checks are presence-only: Raqvio Agent Guardrails never reads, displays or transmits key values.
Each check is pass, warn, fail or info, with a recommended fix.
| Check | What it looks at |
|---|---|
| Enforcement available | Fail if the Abilities API is missing, warning in audit-only mode (WordPress 6.9/7.0), pass when “Policies are enforced on every ability execution.” |
| … API key storage (one per AI provider) | For each AI provider connector that uses an API key (Settings → Connectors in WordPress): pass if the key comes from an environment variable or a wp-config.php constant; warning if it is stored in the database, “where database backups, exports and SQL access can expose it”; info if not configured. |
| MCP Adapter | Whether an MCP server is active. For WooCommerce MCP: “It authenticates with WooCommerce REST API keys; bind those keys’ users as agents.” |
| Publicly exposed abilities | Warning when public/MCP-exposed abilities can change data (lists up to 8), with the fix “Make sure every agent has an explicit allow/deny for these abilities on the Agents screen.” |
| Administrator application passwords | Warning listing administrators who have application passwords — “An agent using one has full admin power.” |
| Dedicated agent users | Pass if at least one user has the AI Agent (Raqvio Agent Guardrails) role; otherwise suggests creating one. |
| Emergency kill switch | Whether the kill switch is currently on. |
How keys are checked without reading them
Section titled “How keys are checked without reading them”- Environment variables and
wp-config.phpconstants are checked for presence only; values are never stored or displayed. - Database storage is detected with
SELECT LENGTH(option_value), so the key itself never leaves MySQL.
To move a key out of the database: define it in wp-config.php or as an environment variable, then remove it from Settings → Connectors. When the provider defines a constant, its exact name is shown in the check’s fix text.