Tool use / function calling
AGrail
AGrail: A Lifelong Agent Guardrail with Effective and Adaptive Safety Detection
Superseded baseline#31 of 55 most-superseded · first seen Feb 17, 2025
Cited as a baseline — critiqued by newer work, not yet beaten on a benchmark here
1 papers critique it · 0 beat it on benchmarks
What papers say
Verbatim critique sentences, each from a paper that cites AGrail as a baseline.
ShieldAgent and AGrail produce safety judgments via complex reasoning and verification pipelines, incurring high latency that makes them impractical for step-level monitoring of tool invocation in LLM-based agents.
What to use instead
Recent methods in the same sub-problem, not yet superseded in the knowledge base — arXiv benchmark leaders, not vetted production recommendations.