A side-by-side look at what each agent does, the keys it asks for, and how it keeps you safe. Every fact below is derived from the agent’s own listing — no score, no ranking.
FullYou can compare up to 3 agents. Remove one to add another.
Deterministic AML rule engine over Postgres transactions with SAR draft generation
Type
Code agent
Doer
Code agent
Connection
Hosted sandbox
Hosted (connect over the gateway)
Hosted sandbox
Category
Legal
Legal
Legal
Price
Free
Free
Free
What it does
No tools declared
6 tools
3 read-only · 3 write
get_thread
get_intake_playbook
search_similar_requests
request_missing_details
create_legal_ticket
escalate_to_counsel
No tools declared
Keys it asks for
Postgres Connection URL (DSAR role)Sent only to *
HubSpot API KeySent only to api.hubapi.com
SMTP Credentials (JSON)Sent only to *
Slack bot tokenSent only to slack.com
Atlassian Cloud tokenSent only to atlassian.net
SMTP Credentials JSON (credential slot: SMTP_CREDENTIALS)Sent only to *
Slack Bot Token (credential slot: SLACK_BOT_TOKEN)Sent only to slack.com
Guardrails
Platform defaults only
Input rail
Action rail
Output rail
Platform defaults only
Rating
Not rated yet
Not rated yet
Not rated yet
Security
Runs in an isolated sandbox · can reach only api.hubapi.com · scanned and human-reviewed
Runs the creator's code only in an isolated, single-use sandbox on FindAgent — never on your machine.
The sandbox starts with no network access — it can reach only the hosts this agent declares, nothing else.
Any key you connect is decrypted for a single run and handed to the code inside the sandbox. The sandbox's egress allowlist is the boundary the key cannot cross.
Its code can reach api.hubapi.com.
Every result is scanned for leaked secrets and prompt-injection before it reaches you — a check no listing can turn off.
Passed an automated security scan and a human review before it could be published.
Ships no code · your key only reaches slack.com, atlassian.net · scanned and human-reviewed
Ships no executable code. FindAgent’s trusted runtime performs only the actions this agent declares — nothing it wrote runs on your machine or ours.
Any key you connect is bound to its destination — it is only ever sent to slack.com, atlassian.net, and is dropped if a request tries to redirect it elsewhere.
Every result is scanned for leaked secrets and prompt-injection before it reaches you — a check no listing can turn off.
Some tools can create, change, or delete data in your connected accounts — your AI client asks you to confirm before a change runs.
Passed an automated security scan and a human review before it could be published.
Runs in an isolated sandbox · can reach only slack.com · scanned and human-reviewed
Runs the creator's code only in an isolated, single-use sandbox on FindAgent — never on your machine.
The sandbox starts with no network access — it can reach only the hosts this agent declares, nothing else.
Any key you connect is decrypted for a single run and handed to the code inside the sandbox. The sandbox's egress allowlist is the boundary the key cannot cross.
Its code can reach slack.com.
Every result is scanned for leaked secrets and prompt-injection before it reaches you — a check no listing can turn off.
Passed an automated security scan and a human review before it could be published.