check_exposed_services
ArrowMem Guard's machine security sweep, given diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Checks whether a model server and common database, search and notebook services are reachable beyond loopback, plus firewall state, disk encryption, screen lock, and pending OS updates - each resolves to PASS, FAIL, or UNVERIFIABLE (never guessed on missing data). The report leads with the highest-severity unresolved finding and names one first action, then lists every result in full with a complete per-OS fix and verify step. States plainly that a service bound wide is not the same claim as internet-reachable (this tool can see local configuration, not your network path). Limits: no signature or malware detection, no behavioural analysis, no filesystem or traffic monitoring. Nothing you submit is stored, logged, or retained; each call is evaluated in isolation. Paid tool - requires a valid API key.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| platform | No | ||
| firewall_status_text | No | ||
| redis_listen_addresses | No | ||
| ollama_listen_addresses | No | ||
| screen_lock_status_text | No | ||
| jupyter_listen_addresses | No | ||
| mongodb_listen_addresses | No | ||
| pending_os_updates_count | No | ||
| postgres_listen_addresses | No | ||
| disk_encryption_status_text | No | ||
| elasticsearch_listen_addresses | No |