🛡️ AgentGuard
Preflight security auditing for AI-agent configuration and MCP — before your agent runs.
Audit your AI agents before they audit your code.
AgentGuard is an open-source CLI and GitHub Action that scans AI-agent instructions and MCP configuration for high-signal security and policy risks.
It is local, deterministic, read-only, and CI-friendly: AgentGuard does not invoke agent tools or connect to configured MCP servers during a normal scan.
Why AgentGuard?
Modern coding agents can read files, run commands, call MCP tools, access secrets, and follow large instruction files. A small configuration mistake can therefore become a security boundary problem.
AgentGuard is the preflight check that runs before the agent:
repository
│
├── agent instructions
├── MCP configuration
├── provider settings
│
▼
┌─────────────────────────────┐
│ AgentGuard │
│ deterministic local audit │
└──────────────┬──────────────┘
│
findings + score
│
┌──────┴──────┐
▼ ▼
local CI
review GitHub checks
Try it in 10 seconds
python -m pip install agentconfigguard
agentguard demo
The demo is synthetic and performs no network access and no file writes.
Then scan a real repository:
agentguard scan .
Useful outputs:
agentguard scan . --json
agentguard scan . --sarif agentguard-results.sarif
agentguard scan . --html agentguard-report.html
agentguard scan . --adapters
agentguard scan . --context
What it checks
| Rule | Detects | Severity |
|---|---|---|
AG-SEC-001 |
Credential-like values in tracked config | High |
AG-EXEC-001 |
Shell / terminal / command-execution capabilities | High |
AG-FS-001 |
Broad filesystem or workspace access | High |
AG-MCP-001 |
MCP trust=true confirmation bypass |
High |
AG-MCP-002 |
Unencrypted remote MCP http:// endpoints |
Medium |
AG-MCP-003 |
Remote MCP servers without provenance metadata | Low |
AG-POLICY-001 |
Untrusted input + private data + outbound actions | Critical |
AG-CODEX-001 |
Codex full-access + no-approval combination | High |
AG-GEMINI-001 |
Gemini persistent approval default | Medium |
AG-OPENCODE-001 |
OpenCode unrestricted shell permission | High |
AG-OPENCODE-002 |
OpenCode unrestricted edit permission | High |
AG-PROMPT-001 |
Common prompt-injection patterns | Medium |
AG-CONTEXT-001 |
Oversized agent instruction files | Low |
AG-CONTEXT-002 |
Instruction files above a configured context budget | Medium |
Supported agent/config markers include Claude, Codex, Cursor, Gemini, OpenCode, and MCP.
GitHub Actions
Add AgentGuard to any repository:
name: AgentGuard
on:
push:
pull_request:
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: atilaamorim/agentguard@v0.2.1
with:
path: .
fail-on-severity: "high"
The Action can emit:
- GitHub annotations
- JSON
- SARIF
- HTML reports
- CI failure gates
It also supports policy files, baselines, and context budgets.
Current stable Action:
v0.2.1. Themainbranch contains the upcomingv0.3.0feature set.
Policy as code
Keep the security gate with the repository:
version: 1
fail_on_severity: high
max_context_tokens: 12000
ignore:
- rule: AG-MCP-002
paths:
- "configs/local/*"
AgentGuard discovers .agentguard.yml / .agentguard.yaml automatically.
Baselines
Existing repositories can adopt AgentGuard without fixing everything at once:
agentguard scan . --write-baseline agentguard-baseline.json
agentguard scan . --baseline agentguard-baseline.json
Only findings that are not already in the baseline are returned.
Pre-commit
repos:
- repo: https://github.com/atilaamorim/agentguard
rev: v0.2.1
hooks:
- id: agentguard
Design principles
| Principle | Meaning |
|---|---|
| Local | No remote service is required for a normal scan |
| Deterministic | The same input should produce reproducible findings |
| Read-only | The scanner does not execute commands from the project |
| Explainable | Findings have stable rule IDs and remediation guidance |
| Composable | CLI, CI, SARIF, HTML, policy, and baseline modes can be combined |
Where AgentGuard fits
AgentGuard is deliberately a static configuration auditor, not a runtime firewall.
| Capability | AgentGuard |
|---|---|
| Local configuration audit | ✅ |
| MCP trust / transport / provenance checks | ✅ |
| Provider-specific checks | ✅ |
| Dangerous capability-chain checks | ✅ |
| JSON / SARIF / HTML | ✅ |
| GitHub Actions | ✅ |
| Policy-as-code | ✅ |
| Baseline mode | ✅ |
| Runtime tool-call enforcement | ❌ |
| Live MCP probing | ❌ |
| LLM-powered verdicts | ❌ |
| Security certification / guarantee | ❌ |
A clean scan is not proof that an agent, MCP server, repository, or deployment is secure. Rules are heuristic and can have false positives or false negatives.
Security regression benchmark
AgentGuard ships deterministic risky and safe fixtures under tests/fixtures/.
Run the suite locally:
pytest -q
Rules should include positive and negative regression coverage whenever practical.
Documentation
Roadmap
- Local filesystem scanner
- JSON/YAML MCP inspection
- Secret detection
- Prompt-injection heuristics
- Permission-risk heuristics
- MCP trust / cleartext HTTP checks
- Dangerous capability-chain detection
- Claude / Codex / Cursor / Gemini / OpenCode detection
- JSON / SARIF / HTML output
- GitHub Action
- GitHub annotations
- Context-cost estimation
- Context budget gate
- Baseline mode
- Policy-as-code
- PyPI package metadata
- Expand provider-specific coverage
- Add more safe/risky MCP provenance cases
- Improve interactive demo and onboarding
- Add more integrations and examples
Contributing
Good starting points:
- #12 — Add more MCP provenance regression cases
- #13 — Improve AgentGuard demo and onboarding examples
Small, focused pull requests are welcome. New security rules should include regression coverage and remediation guidance.
Security issues should follow SECURITY.md.
License
MIT
Metadata
Release files for agentconfigguard 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agentconfigguard-0.3.0.tar.gz | 19.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agentconfigguard-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 37.3 kB
Release files / agentconfigguard-0.3.0.tar.gz
| Download URL | agentconfigguard-0.3.0.tar.gz |
|---|---|
| Size | 19.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d32b067bf02069e412d3a2625da981d57217ea2e982168bd87a3b062b71d7797
|
|
BLAKE2b-256 checksum How to use checksums |
e0dea1a15e475df0c651e59f4433f9887f03ddc97bfc2a1c85ec91d1865c1168
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency logRelease files / agentconfigguard-0.3.0-py3-none-any.whl
| Download URL | agentconfigguard-0.3.0-py3-none-any.whl |
|---|---|
| Size | 18.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
bdca70ec76a6b21711e7419117fc128353199f208e3156a06940997b17497915
|
|
BLAKE2b-256 checksum How to use checksums |
4b0042fdd1f7e70181cd9afa6a69fcfa625fb99d635ecd6d74aeaf365f1d9900
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency log