Agent firewalls are the wrong abstraction
Dangerous agent actions are better constrained with permissions and sandboxing than inferred after the fact by an AI runtime security layer
My current advice on AI agent security is to avoid these agent firewalls / ai runtime security products. If an action is dangerous enough that you can identify it from the action itself, then you could have prevented it with permissions an