Skip to main content

🛡️ AgentGuard

Preflight security auditing for AI-agent configuration and MCP — before your agent runs.

Tests PyPI PyPI downloads Python License GitHub stars

Audit your AI agents before they audit your code.

AgentGuard is an open-source CLI and GitHub Action that scans AI-agent instructions and MCP configuration for high-signal security and policy risks.

It is local, deterministic, read-only, and CI-friendly: AgentGuard does not invoke agent tools or connect to configured MCP servers during a normal scan.

Why AgentGuard?

Modern coding agents can read files, run commands, call MCP tools, access secrets, and follow large instruction files. A small configuration mistake can therefore become a security boundary problem.

AgentGuard is the preflight check that runs before the agent:

repository
   │
   ├── agent instructions
   ├── MCP configuration
   ├── provider settings
   │
   ▼
┌─────────────────────────────┐
│         AgentGuard          │
│  deterministic local audit  │
└──────────────┬──────────────┘
               │
        findings + score
               │
        ┌──────┴──────┐
        ▼             ▼
      local           CI
      review       GitHub checks

Try it in 10 seconds

python -m pip install agentconfigguard
agentguard demo

The demo is synthetic and performs no network access and no file writes.

Then scan a real repository:

agentguard scan .

Useful outputs:

agentguard scan . --json
agentguard scan . --sarif agentguard-results.sarif
agentguard scan . --html agentguard-report.html
agentguard scan . --adapters
agentguard scan . --context

What it checks

Rule Detects Severity
AG-SEC-001 Credential-like values in tracked config High
AG-EXEC-001 Shell / terminal / command-execution capabilities High
AG-FS-001 Broad filesystem or workspace access High
AG-MCP-001 MCP trust=true confirmation bypass High
AG-MCP-002 Unencrypted remote MCP http:// endpoints Medium
AG-MCP-003 Remote MCP servers without provenance metadata Low
AG-POLICY-001 Untrusted input + private data + outbound actions Critical
AG-CODEX-001 Codex full-access + no-approval combination High
AG-GEMINI-001 Gemini persistent approval default Medium
AG-OPENCODE-001 OpenCode unrestricted shell permission High
AG-OPENCODE-002 OpenCode unrestricted edit permission High
AG-PROMPT-001 Common prompt-injection patterns Medium
AG-CONTEXT-001 Oversized agent instruction files Low
AG-CONTEXT-002 Instruction files above a configured context budget Medium

Supported agent/config markers include Claude, Codex, Cursor, Gemini, OpenCode, and MCP.

GitHub Actions

Add AgentGuard to any repository:

name: AgentGuard

on:
  push:
  pull_request:

jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7
      - uses: atilaamorim/agentguard@v0.3.1
        with:
          path: .
          fail-on-severity: "high"

The Action can emit:

  • GitHub annotations
  • JSON
  • SARIF
  • HTML reports
  • CI failure gates

It also supports policy files, baselines, and context budgets.

Current stable Action: v0.3.1. The main branch contains the upcoming v0.3.0 feature set.

Policy as code

Keep the security gate with the repository:

version: 1
fail_on_severity: high
max_context_tokens: 12000

ignore:
  - rule: AG-MCP-002
    paths:
      - "configs/local/*"

AgentGuard discovers .agentguard.yml / .agentguard.yaml automatically.

Baselines

Existing repositories can adopt AgentGuard without fixing everything at once:

agentguard scan . --write-baseline agentguard-baseline.json
agentguard scan . --baseline agentguard-baseline.json

Only findings that are not already in the baseline are returned.

Pre-commit

repos:
  - repo: https://github.com/atilaamorim/agentguard
    rev: v0.3.1
    hooks:
      - id: agentguard

Design principles

Principle Meaning
Local No remote service is required for a normal scan
Deterministic The same input should produce reproducible findings
Read-only The scanner does not execute commands from the project
Explainable Findings have stable rule IDs and remediation guidance
Composable CLI, CI, SARIF, HTML, policy, and baseline modes can be combined

Where AgentGuard fits

AgentGuard is deliberately a static configuration auditor, not a runtime firewall.

Capability AgentGuard
Local configuration audit ✅
MCP trust / transport / provenance checks ✅
Provider-specific checks ✅
Dangerous capability-chain checks ✅
JSON / SARIF / HTML ✅
GitHub Actions ✅
Policy-as-code ✅
Baseline mode ✅
Runtime tool-call enforcement ❌
Live MCP probing ❌
LLM-powered verdicts ❌
Security certification / guarantee ❌

A clean scan is not proof that an agent, MCP server, repository, or deployment is secure. Rules are heuristic and can have false positives or false negatives.

Security regression benchmark

AgentGuard ships deterministic risky and safe fixtures under tests/fixtures/.

Run the suite locally:

pytest -q

Rules should include positive and negative regression coverage whenever practical.

Documentation

Roadmap

  • Local filesystem scanner
  • JSON/YAML MCP inspection
  • Secret detection
  • Prompt-injection heuristics
  • Permission-risk heuristics
  • MCP trust / cleartext HTTP checks
  • Dangerous capability-chain detection
  • Claude / Codex / Cursor / Gemini / OpenCode detection
  • JSON / SARIF / HTML output
  • GitHub Action
  • GitHub annotations
  • Context-cost estimation
  • Context budget gate
  • Baseline mode
  • Policy-as-code
  • PyPI package metadata
  • Expand provider-specific coverage
  • Add more safe/risky MCP provenance cases
  • Improve interactive demo and onboarding
  • Add more integrations and examples

Contributing

Good starting points:

Small, focused pull requests are welcome. New security rules should include regression coverage and remediation guidance.

Security issues should follow SECURITY.md.

License

MIT

Metadata

Release files for agentconfigguard 0.3.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentconfigguard 0.3.1
File Size Uploaded
agentconfigguard-0.3.1.tar.gz 19.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentconfigguard 0.3.1
File Interpreter ABI Platform
agentconfigguard-0.3.1-py3-none-any.whl Python 3 none any Details

Total release size: 37.3 kB

Release files / agentconfigguard-0.3.1.tar.gz

Download URL agentconfigguard-0.3.1.tar.gz
Size 19.2 kB
Tags Source
SHA-256 checksum
How to use checksums
1f59853901bae0c08b43c8770fe4906a7a6a08f66780adb85e86dc2dc586086b
BLAKE2b-256 checksum
How to use checksums
799ee1d75704735bd392435e4775b0d42a679c65b58afe1af09e9a561ac33068
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release files / agentconfigguard-0.3.1-py3-none-any.whl

Download URL agentconfigguard-0.3.1-py3-none-any.whl
Size 18.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ee4ab09717571bd2ffb6a4e0470ecca96272799b40577c9098b881b899eebb9f
BLAKE2b-256 checksum
How to use checksums
21e4a39999128ccb012d5129ca8d458bb877729109f0ced8c478bab75c8223ac
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.1 This release

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page