Skip to main content

Safety checks an AI agent runs before it acts: is this package malware/typosquat, is this shell command destructive, does this text leak a secret. CLI + MCP server.

Project description

agent-guard

The safety check an AI agent runs before it acts.

Every agent that installs packages, runs shell commands, or commits/outputs text can do real damage: install malware, wipe a disk, or leak a credential. agent-guard is three cheap, dependency-free checks — the "look before you leap" gate an agent (or you) calls before the irreversible step.

pip install agent-tripwire            # the checks (zero deps)
pip install "agent-tripwire[mcp]"     # + the MCP server for agents

Use it as an MCP tool (for agents)

An agent can call these itself before acting. Add to your MCP client (Claude/Cursor/Claude Code):

{ "mcpServers": { "agent-guard": { "command": "agent-guard-mcp" } } }

MCP registry identity — mcp-name: io.github.ipezygj/agent-guard

tool the agent calls it before…
check_package pip/npm install — is it real, malware, a typosquat, or does it run code on install?
check_command running a shell command — is it a destructive / remote-code-exec vector (rm -rf, curl|bash, dd, force-push)?
scan_secrets committing / pasting / logging — does the text leak an API key, token, or private key?
scan_project deploying / shipping a web backend — fail-open auth, unsigned payment webhooks, SQL injection, SSRF, hardcoded secrets?

The checks

check_package — existence on the registry (a hallucinated name is a red flag), typosquat distance to popular packages, npm install/postinstall scripts (the classic supply-chain malware vector), and OSV malware/vulnerability advisories. Mainstream packages pass; look-alikes and install-time-code flag.

check_command — matches destructive / RCE shell patterns with a severity and a plain reason. rm -rf /, curl … | bash, dd of=/dev/sda, fork bombs → critical; force-push, hard-reset, sudo, DROP TABLE → high.

scan_secrets — AWS/OpenAI/Anthropic/Google/Stripe/GitHub/Slack keys, private-key blocks, JWTs, and generic api_key=/password= assignments. Returns each finding (type, line, redacted).

scan_project — reads a web/API backend (directory or single .py) for the money-losing logic bugs a secret- or command-scanner can't see: auth that fails open when a secret is unset, payment webhooks with no signature check (a forged checkout mints free credits), SQL built by string interpolation, SSRF-able f-string URLs, and secrets hardcoded as defaults. Each finding gives the file, line, why, and the fix. FP-disciplined: parameterized SQL, signed webhooks, and fail-closed guards stay silent.

from agent_guard import analyze_command, scan_secrets, check_package
from agent_guard.webscan import scan_project
analyze_command("rm -rf /")["danger"]           # "critical"
scan_secrets("token = 'ghp_...'")["leaked"]     # True
check_package("reqwests", "pypi")["risk"]       # "high" (typosquat of requests)
scan_project("./my_api")["risk"]                # "critical" if a webhook skips signature checks

The point: an agent about to install/run/commit should check first — and now it can, in one call, with a plain verdict and a recommendation. If a check comes back high/critical, stop and get a human.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent_tripwire-0.2.0.tar.gz (16.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agent_tripwire-0.2.0-py3-none-any.whl (17.5 kB view details)

Uploaded Python 3

File details

Details for the file agent_tripwire-0.2.0.tar.gz.

File metadata

  • Download URL: agent_tripwire-0.2.0.tar.gz
  • Upload date:
  • Size: 16.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for agent_tripwire-0.2.0.tar.gz
Algorithm Hash digest
SHA256 d8cff492c17aa2932e786605c60de4312c6b64b4a2d79209e0df0379cea62422
MD5 81b222979386c5c5bb7ae99f6e8cd060
BLAKE2b-256 5ad50d1ffee302ae223bdbf39acb5e7014e132c7fc7c8cf6b95418f2309e7dc1

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_tripwire-0.2.0.tar.gz:

Publisher: publish.yml on ipezygj/agent-guard

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent_tripwire-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: agent_tripwire-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 17.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for agent_tripwire-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 4dddb3c128322b704e929cd236fcd0ad3965a926742d610a973da1374b89dc10
MD5 695022255045db6992ac721f1a7cb90a
BLAKE2b-256 6430d6bfcfdfaddfdb2521788cfaacb665283028cf3e7ee8ef94f3f7f61cd459

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_tripwire-0.2.0-py3-none-any.whl:

Publisher: publish.yml on ipezygj/agent-guard

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page