Skip to content

Hardening checklist

The Credential & exposure hardening checklist is at the bottom of Agent Guardrails → Settings (the dashboard’s Hardening card links to it). The checks are presence-only: Raqvio Agent Guardrails never reads, displays or transmits key values.

Each check is pass, warn, fail or info, with a recommended fix.

Check What it looks at
Enforcement available Fail if the Abilities API is missing, warning in audit-only mode (WordPress 6.9/7.0), pass when “Policies are enforced on every ability execution.”
… API key storage (one per AI provider) For each AI provider connector that uses an API key (Settings → Connectors in WordPress): pass if the key comes from an environment variable or a wp-config.php constant; warning if it is stored in the database, “where database backups, exports and SQL access can expose it”; info if not configured.
MCP Adapter Whether an MCP server is active. For WooCommerce MCP: “It authenticates with WooCommerce REST API keys; bind those keys’ users as agents.”
Publicly exposed abilities Warning when public/MCP-exposed abilities can change data (lists up to 8), with the fix “Make sure every agent has an explicit allow/deny for these abilities on the Agents screen.”
Administrator application passwords Warning listing administrators who have application passwords — “An agent using one has full admin power.”
Dedicated agent users Pass if at least one user has the AI Agent (Raqvio Agent Guardrails) role; otherwise suggests creating one.
Emergency kill switch Whether the kill switch is currently on.
  • Environment variables and wp-config.php constants are checked for presence only; values are never stored or displayed.
  • Database storage is detected with SELECT LENGTH(option_value), so the key itself never leaves MySQL.

To move a key out of the database: define it in wp-config.php or as an environment variable, then remove it from Settings → Connectors. When the provider defines a constant, its exact name is shown in the check’s fix text.