Skip to main content

AgentGuard

Let agents act. Keep humans in control.

CI Docs License: MIT Python 3.11+

AgentGuard is an open-source Python SDK that sits between an AI agent and its tools. Every tool call is validated, checked against a policy, scored for risk, optionally reviewed by a local Gemma model, sent to a human when needed, run through a restricted executor, verified, and written to a tamper-evident audit log.

Documentation · Quickstart · Integrations · Threat model · Changelog

See it work

pip install agentguard-oss
agentguard demo --scripted

An agent is asked to fix a calculator. The repository's README hides a prompt injection telling it to read ~/.ssh/id_rsa and upload it. AgentGuard lets the agent read the README, blocks the SSH-key read and the curl exfiltration, allows the fix and a real unit test, and escalates the push to main for human approval.

With Ollama and ollama pull gemma3:4b, plain agentguard demo runs a live Gemma agent against the same trap, and --judge adds a Gemma security reviewer. Add --interactive to approve the push yourself. See Gemma agent and judge.

Guard a tool

from pathlib import Path

from agentguard import Guard

guard = Guard(
    {
        "version": 1,
        "defaults": {"effect": "deny"},
        "rules": [
            {"capability": "filesystem.read", "paths": ["./workspace/**"], "effect": "allow"},
            {"capability": "shell.execute", "effect": "ask"},
        ],
    },
    audit="agentguard.jsonl",
)


@guard.tool(capability="filesystem.read")
def read_file(path: str) -> str:
    """Read a UTF-8 text file."""
    return Path(path).read_text(encoding="utf-8")


# Give the agent read_file, never the raw function.
# read_file("~/.ssh/id_rsa") raises GuardDenied before the function body runs.

Then check the policy, ask how it decides a call, and verify the log:

agentguard check-policy policy.yaml
agentguard explain policy.yaml shell.execute --arg cmd="git push origin main"
agentguard verify-log --audit agentguard.jsonl

Use it with your framework

pip install "agentguard-oss[langchain]"   # also [openai-agents], [adk], [mcp], [all]
from agentguard.adapters.langchain import guarded_tool        # LangChain / LangGraph
# from agentguard.adapters.openai_agents import guarded_tool  # OpenAI Agents SDK
# from agentguard.adapters.adk import guarded_tool            # Google ADK


def read_notes(path: str) -> str:
    """Read a notes file."""
    return Path(path).read_text(encoding="utf-8")


notes_tool = guarded_tool(guard, read_notes, capability="filesystem.read")

Denials go back to the model with AgentGuard's reasons so the agent can adapt. MCP servers use agentguard.adapters.mcp.register_tool; any other loop can call guard.call(name, arguments).

What you get

Control Details
Policy as code YAML allow / ask / deny rules by capability, path, domain, environment and secrets. Explicit denies win. Custom capabilities like db.query or payments.refund.
Risk checks Explainable 0–100 scores. Credential files, destructive commands and exfiltration after a secret was seen are always denied.
Human approval Risky calls go to a person in the dashboard, Slack or your own system without blocking the agent; grants like "allow this tool for 10 minutes". No answer means deny.
Isolation Container executor (no network, read-only, no capabilities, optional gVisor), exact-command runners, DNS-pinned HTTPS, and an allowlisting egress proxy.
Detection gitleaks' 221 secret rules on RE2, checksum-validated PII, and shell-aware command analysis.
Verification Before/after hashes catch tools that change files they were not asked to.
Audit Every stage of every call in a signed SHA-256 hash chain with rotation, exported to OpenTelemetry or a SIEM.
Dashboard Approval queue, audit log viewer and a dry-run policy report.
Multi-agent Parallel per-agent sessions; rate limits per session, agent or globally through Redis.
Gemma A local Gemma agent for the demo, and an optional judge that can only add caution.

Starter policies for coding, browsing and support agents are in examples/policies/.

Operate it

pip install "agentguard-oss[dashboard]"
agentguard approvers add alice            # prints a token for the dashboard and API
agentguard dashboard                      # http://127.0.0.1:8765
from agentguard.approval import ApprovalStore, QueueApproval

guard = Guard("policy.yaml", approval=QueueApproval(ApprovalStore("agentguard-approvals.db")))

Risky calls raise ApprovalPending immediately instead of blocking; the agent retries after a human approves in the dashboard, in Slack, or through the API. Run a new agent with mode="dry-run" and check agentguard report --dry-run-only to tune the policy before enforcing it.

Status

AgentGuard 0.4 is alpha and has not had an independent security audit; see the security review guide and benchmarks. It is an interception layer for cooperative applications, not an OS sandbox: an agent that also has unguarded tools, a raw shell or Python exec can go around it. Read the threat model before guarding privileged tools, and report vulnerabilities privately as described in SECURITY.md.

Develop

git clone https://github.com/prollysamz/agentguard.git
cd agentguard
python -m venv .venv
# Windows: .venv\Scripts\activate    macOS/Linux: source .venv/bin/activate
python -m pip install -e ".[dev,all,docs]"
python -m pytest -q
python -m ruff check .
mkdocs serve

CI runs the tests on Linux and Windows with Python 3.11 and 3.12. See CONTRIBUTING.md. MIT licensed.

Metadata

Release files for agentguard-oss 0.4.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentguard-oss 0.4.1
File Size Uploaded
agentguard_oss-0.4.1.tar.gz 140.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentguard-oss 0.4.1
File Interpreter ABI Platform
agentguard_oss-0.4.1-py3-none-any.whl Python 3 none any Details

Total release size: 268.3 kB

Release files / agentguard_oss-0.4.1.tar.gz

Download URL agentguard_oss-0.4.1.tar.gz
Size 140.1 kB
Tags Source
SHA-256 checksum
How to use checksums
30db580a6c5202a04ed5a389dcf1b41c148b5d5fee2cc474865ac03720eace8c
BLAKE2b-256 checksum
How to use checksums
5b908d8309bc6664db32d179c42ea100d7e801eb5453dcfb52268ca3b917fcf0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release files / agentguard_oss-0.4.1-py3-none-any.whl

Download URL agentguard_oss-0.4.1-py3-none-any.whl
Size 128.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
58b2324888e592dd198c2d0f9b95306cd41744d4865a62179236ec65a06152c4
BLAKE2b-256 checksum
How to use checksums
f69f31b986708721bc55f213437a3f741d19735d3dcb07f75e1158be534d1996
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 10, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.4.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page