Skip to main content

🛡️ AgentGuard

Tests PyPI PyPI downloads License

Security and context auditor for AI agents and MCP servers.

Audit your AI agents before they audit your code.

AgentGuard is an open-source CLI that scans agent instructions, MCP configuration, and project text for common security risks and produces machine-readable reports for CI.

Static and local by design: the scanner analyzes files without connecting to agents or invoking MCP tools during the audit.

What it checks

Rule What it looks for Severity
AG-SEC-001 API keys, tokens, passwords and private-key material High
AG-EXEC-001 Shell, terminal and command-execution capabilities High
AG-FS-001 Broad filesystem/workspace access in config High
AG-MCP-001 MCP servers configured with trust=true High
AG-MCP-002 MCP servers using unencrypted http:// endpoints Medium
AG-MCP-003 Remote MCP servers without declared provenance metadata Low
AG-POLICY-001 Dangerous combination of untrusted input, private data access and outbound actions Critical
AG-GEMINI-001 Gemini CLI persistent approval default Medium
AG-CODEX-001 Codex full-access approval combination High
AG-PROMPT-001 Common prompt-injection instruction patterns Medium
AG-CONTEXT-001 Oversized agent instruction files Low
AG-CONTEXT-002 Agent context above a configured token budget Medium

The scanner also understands common agent instruction files such as CLAUDE.md, AGENTS.md, GEMINI.md, CODEX.md, and CURSOR.md.

Quick start

Install the latest public release from PyPI:

python -m pip install agentconfigguard
agentguard --version
agentguard scan .

The PyPI distribution is named agentconfigguard; the CLI command remains agentguard.

For development or unreleased code:

git clone https://github.com/atilaamorim/agentguard.git
cd agentguard
python -m pip install -e .
agentguard scan .

For a development install directly from GitHub:

python -m pip install git+https://github.com/atilaamorim/agentguard.git
agentguard --version

You can also run:

python -m agentguard scan .

Try it in 10 seconds

Run the built-in local demonstration:

agentguard demo

The demo uses a synthetic MCP configuration and performs no network access or file writes. Use agentguard demo --json for machine-readable output.

JSON output

agentguard scan . --json

SARIF output

SARIF works well with GitHub code-scanning workflows:

agentguard scan . --sarif agentguard-results.sarif

HTML report

agentguard scan . --html agentguard-report.html

MCP security checks

AgentGuard parses common mcpServers / MCP server configuration structures and checks for high-signal hazards:

  • trust: true — flags configurations that can bypass normal tool-call confirmation.
  • url: http://... (and equivalent endpoint keys) — flags unencrypted remote MCP transport.
  • Capability-chain analysis — flags a server that combines untrusted input, private-data access, and outbound actions.

HTTPS endpoints are not flagged by the HTTP transport check. Remote MCP servers without declared provenance metadata also receive a low-severity transparency warning.

Ecosystem detection

See which AI-agent ecosystems are present in a project:

agentguard scan . --adapters

AgentGuard currently recognizes Claude, Codex, Cursor, Gemini, OpenCode, and MCP configuration markers.

Context cost estimate

See which agent instruction files consume the most context:

agentguard scan . --context

Token counts are estimates based on character length, not provider-specific billing.

Context budget gate

Enforce a project-level context budget in CI:

agentguard scan . --max-context-tokens 12000

AgentGuard reports AG-CONTEXT-002 when a supported instruction file exceeds the configured budget. Token counts are estimates based on character length, not provider-specific billing.

Pre-commit

Run AgentGuard before each commit:

repos:
  - repo: https://github.com/atilaamorim/agentguard
    rev: v0.2.1
    hooks:
      - id: agentguard

The hook blocks commits on high and critical findings by default.

Policy as code

Add .agentguard.yml to the project root to keep CI policy with the repository:

version: 1
fail_on_severity: high
max_context_tokens: 12000
ignore:
  - rule: AG-MCP-002
    paths:
      - "configs/local/*"

The file is discovered automatically. Use --policy PATH to select another file or --no-policy to disable automatic discovery.

CLI flags take precedence over policy values.

CI severity threshold

Keep lower-severity findings visible without failing the build:

agentguard scan . --fail-on-severity high

With this setting, high and critical findings fail CI while medium and low findings remain visible in reports.

The reusable GitHub Action exposes the same control:

      - uses: atilaamorim/agentguard@v0.2.1
        with:
          fail-on-severity: "high"

GitHub Actions annotations

When running in GitHub Actions, emit inline warnings and errors for findings:

agentguard scan . --github-annotations

The reusable GitHub Action enables annotations by default. Disable them when desired:

      - uses: atilaamorim/agentguard@v0.2.1
        with:
          github-annotations: "false"

Baseline mode

For existing projects, create a baseline and then fail CI only when new findings appear:

agentguard scan . --write-baseline agentguard-baseline.json
agentguard scan . --baseline agentguard-baseline.json

Baseline matching uses the rule, file path, and detected evidence. Review the baseline periodically as the project changes.

GitHub Action

Use AgentGuard directly in another repository:

name: AgentGuard

on:
  push:
  pull_request:

jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v7
      - uses: atilaamorim/agentguard@v0.2.1
        with:
          path: .

You can also enforce the context budget through the action:

      - uses: atilaamorim/agentguard@v0.2.1
        with:
          max-context-tokens: "12000"
          fail-on-findings: "true"

The action automatically discovers .agentguard.yml in the target repository. To select a different policy file:

      - uses: atilaamorim/agentguard@v0.2.1
        with:
          policy: "config/agentguard.yml"

To make findings fail the job:

      - uses: atilaamorim/agentguard@v0.2.1
        with:
          fail-on-findings: "true"

Example

🛡️ AgentGuard 0.2.1

Scanning: .

Security score: 71/100
Findings: 3

HIGH     AG-SEC-001      Potential secret detected — .env:4
HIGH     AG-EXEC-001     Potential command execution capability — AGENTS.md:12
MEDIUM   AG-PROMPT-001   Prompt-injection pattern detected — CLAUDE.md:8

A non-clean scan exits with status code 1, which makes AgentGuard suitable for CI gates.

Architecture

See docs/architecture.md for the scanner flow, safety boundaries, and extension model.

Threat model

See docs/threat-model.md for scope, limitations, and false-positive guidance.

Rule reference

See docs/rules.md for the current rule catalog, severity, rationale, and remediation guidance.

Security regression benchmark

AgentGuard ships with small, deterministic MCP fixtures under tests/fixtures/.

Run the full regression suite with:

pytest -q

The benchmark intentionally includes both dangerous and safe configurations. The goal is not only to detect risky capability combinations, but also to protect against future false positives as new rules are added.

Why AgentGuard?

AI agents increasingly receive access to terminals, files, credentials, MCP tools, and large instruction files. A configuration that looks harmless to a human can create meaningful security or privacy risk.

AgentGuard aims to make that risk visible before an agent runs.

Project status

AgentGuard is an early public MVP. Detection is heuristic and can produce false positives or miss sophisticated attacks. It is an auditing aid, not a guarantee that an agent, MCP server, repository, or deployment is secure.

Roadmap

  • Local filesystem scanner
  • JSON/YAML MCP config inspection
  • Secret detection
  • Prompt-injection heuristics
  • Permission-risk heuristics
  • MCP trust-bypass detection
  • MCP insecure-HTTP detection
  • Dangerous capability-chain detection
  • Gemini CLI persistent approval detection
  • Codex full-access approval detection
  • Security score
  • JSON output
  • SARIF output
  • Reusable GitHub Action
  • Context bloat detection
  • GitHub Action annotations
  • Ecosystem detection for Claude Code, Codex, Cursor, Gemini CLI and OpenCode
  • Sanitized provider configuration fixtures for supported ecosystems
  • MCP registry / server metadata checks (provenance metadata)
  • Context-cost estimation
  • Configurable context-token CI gate
  • HTML report
  • Baseline mode for CI
  • Versioned policy-as-code configuration
  • PyPI package publication as agentconfigguard

Contributing

See CONTRIBUTING.md.

Security issues should follow SECURITY.md.

License

MIT

Metadata

Release files for agentconfigguard 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentconfigguard 0.2.1
File Size Uploaded
agentconfigguard-0.2.1.tar.gz 18.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentconfigguard 0.2.1
File Interpreter ABI Platform
agentconfigguard-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 36.1 kB

Release files / agentconfigguard-0.2.1.tar.gz

Download URL agentconfigguard-0.2.1.tar.gz
Size 18.4 kB
Tags Source
SHA-256 checksum
How to use checksums
1f996ed3975a9e3d9a3c4d61f1c848ea1e05d4dda207a78c58906f1c54d91c53
BLAKE2b-256 checksum
How to use checksums
c996d485a7bd02139e3d9cfc441b7d9cc0a473a7e9ee490ef0727fa60a0564fd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / agentconfigguard-0.2.1-py3-none-any.whl

Download URL agentconfigguard-0.2.1-py3-none-any.whl
Size 17.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3dc56be6c25145dbe0c6de8acbca825e1a58ebabb6f0e8b910ba41e1dd37a00d
BLAKE2b-256 checksum
How to use checksums
b990a56cb7712c2304a73420f3dfac6e57c350173eff1b9babf01c377f5dcb05
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.1

2 release files

0.3.0

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page