AgentGuard
Autonomous security scanner for AI agents. Detects prompt injection, tool abuse, data exfiltration, and OWASP ASI Top 10 vulnerabilities in agent code.
Why AgentGuard?
AI agents are being deployed at scale -- in coding tools, customer support, trading bots, and autonomous systems. Nobody is scanning their code for security vulnerabilities.
Existing tools (Bandit, Semgrep, CodeQL) scan for traditional vulnerabilities. AgentGuard scans for agent-specific attack vectors that traditional SAST tools miss.
Comparison
| Feature | AgentGuard | Semgrep | CodeQL | Bandit |
|---|---|---|---|---|
| Prompt Injection (ASI01) | Yes + AST taint | No | No | No |
| Tool Abuse (ASI02) | Yes | No | No | Partial |
| Data Exfiltration (ASI03) | Yes | No | No | No |
| Excessive Agency (ASI04) | Yes | No | No | No |
| Supply Chain (ASI05) | Yes | No | No | No |
| Insecure Output (ASI06) | Yes | No | No | No |
| Credential Exposure (ASI07) | Yes | Partial | Partial | Yes |
| Context Manipulation (ASI08) | Yes | No | No | No |
| Agent Loop Exploitation (ASI09) | Yes | No | No | No |
| Trust Boundary (ASI10) | Yes | No | No | No |
| AST Taint Tracking | Yes | No | No | No |
| OWASP ASI Top 10 Coverage | 10/10 | 1/10 | 1/10 | 2/10 |
| MCP Server Mode | Yes | No | No | No |
| SARIF Output | Yes | Yes | Yes | No |
| Pre-commit Hook | Yes | Yes | No | No |
| GitHub Action | Yes | Yes | Yes | No |
Live Demo
See AgentGuard in action on the demo repo. The CI runs AgentGuard on every push, and findings appear in GitHub Code Scanning.
Sovereign Security Audit 2026
AgentGuard was deployed against 6 major AI agent frameworks:
| Framework | Stars | Files | Findings | CRITICAL |
|---|---|---|---|---|
| LlamaIndex | 35K | 2,951 | 1,003 | 252 |
| CAMEL | 17K | 899 | 746 | 387 |
| LangChain | 95K | 1,784 | 452 | --- |
| Qwen-Agent | 16K | 239 | 441 | 263 |
| CrewAI | 25K | 84 | 391 | --- |
| AutoGen | 53K | 549 | 229 | 80 |
| TOTAL | 6,506 | 3,262 | 982+ |
Full report: AUDIT_REPORT_2026.md
AgentGuard is the first and only static analysis tool with dedicated OWASP ASI Top 10 rules. Traditional SAST tools (Semgrep, CodeQL, Bandit) lack agent-specific detection rules -- they were designed for traditional vulnerabilities, not AI agent attack vectors.
Security Specification: SPECIFICATION.md — the formal standard for AI agent code security.
Quick Start
pip install dfx-agentguard
# Scan a directory
agentguard .
# JSON output for CI/CD
agentguard src/ --format json
# SARIF for GitHub Code Scanning
agentguard . --format sarif > results.sarif
# Only show HIGH and above
agentguard . --min-severity HIGH
# Include test files in scan
agentguard . --include-tests
CLI Usage
agentguard [OPTIONS] [TARGET]
Arguments:
TARGET Directory or file to scan (default: current directory)
Options:
--format [text|json|sarif] Output format (default: text)
--exit-code / --no-exit-code Exit non-zero if findings found (default: on)
--min-severity [CRITICAL|HIGH|MEDIUM|LOW|INFO] Minimum severity to report
--include-tests Include test files in scan (default: skip)
--help Show help
OWASP ASI Top 10 Coverage
| ID | Vulnerability | Status | Detection Method |
|---|---|---|---|
| ASI01 | Prompt Injection | Detected | f-string, .format(), messages array, context stuffing, tool description poisoning |
| ASI02 | Tool Abuse / Unintended Tool Use | Detected | os.system, subprocess, shell tools, unrestricted registration |
| ASI03 | Data Exfiltration | Detected | External URLs, variable URL correlation, fetch/axios, subprocess curl, DNS exfil |
| ASI04 | Unauthorized Actions / Excessive Agency | Detected | Auto-execute, no confirmation, autonomous actions |
| ASI05 | Supply Chain / Untrusted Components | Detected | Dynamic import, unpinned deps, untrusted pip install |
| ASI06 | Insecure Output Handling | Detected | LLM output in HTML/JSX/DOM, innerHTML, document.write, markdown.render |
| ASI07 | Credential / Secret Exposure | Detected | API keys (sk-, ghp_, AKIA, AIza, xox), private keys, passwords, connection strings |
| ASI08 | Context Window Manipulation | Detected | Unbounded context, token stuffing, missing limits |
| ASI09 | Agent Loop Exploitation | Detected | Recursive calls without depth limit, while True, no max iterations |
| ASI10 | Trust Boundary Violation | Detected | Root access, host filesystem mounts, no sandbox, self-modification |
CI/CD Integration
Docker — Run Anywhere
docker run --rm -v $(pwd):/workspace ghcr.io/dockfixlabs/agentguard .
Works in any CI/CD pipeline. No Python needed.
GitHub Action
name: Security Scan
on: [push, pull_request]
jobs:
agentguard:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- run: pip install dfx-agentguard
- run: agentguard . --format sarif > results.sarif
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarif
Drop-in GitHub Action
- uses: dockfixlabs/agentguard@v0.4.0
with:
path: src/
format: sarif
Pre-commit Hook
repos:
- repo: https://github.com/dockfixlabs/agentguard
rev: v0.4.0
hooks:
- id: agentguard
args: ["--min-severity", "HIGH"]
Programmatic Usage
from agentguard.scanner import scan_directory
result = scan_directory("src/")
print(f"Found {len(result.findings)} issues")
print(f"Critical: {result.critical_count}")
print(f"High: {result.high_count}")
for finding in result.findings:
print(f" [{finding.severity}] {finding.rule_name} at {finding.file}:{finding.line}")
MCP Server Mode
Scan agent code directly from Claude Code, Cursor, or any MCP-compatible client:
{
"mcpServers": {
"agentguard": {
"command": "python3",
"args": ["-m", "agentguard.mcp_server"]
}
}
}
Then ask Claude: "Scan my agent code for security vulnerabilities"
Benchmark Results
Tested against 28 vulnerable code samples + 8 real-world attack patterns:
Category Total Detected Coverage
ASI01 6 6 Covered
ASI02 5 5 Covered
ASI03 4 4 Covered
ASI07 6 6 Covered
ASI10 5 5 Covered
clean 2 0 Verified clean
TOTAL 28 26 —
56 hand-crafted benchmark samples demonstrate comprehensive rule coverage.
Project Ecosystem
| Repository | Description |
|---|---|
| agentguard | Core scanner + CLI + MCP server |
| mcp-scanner | MCP server configuration scanner |
| agentguard-app | GitHub App for automated PR reviews |
| agentguard-vscode | VS Code extension |
| agentguard-benchmark | Benchmark suite (28 samples) |
Roadmap
- OWASP ASI Top 10 -- all 10 categories covered
- MCP server mode -- scan from Claude Code/Cursor
- SARIF output -- GitHub Code Scanning integration
- PyPI publication -- dfx-agentguard
- VS Code extension
- GitHub App for PR reviews
- Benchmark suite (28 samples, covering all detection rules)
- Pre-commit hook (.pre-commit-hooks.yaml)
- GitHub Action (action.yml)
- Dockerfile for agentguard-app
- PyPI Trusted Publishing (OIDC)
- AST-based taint tracking (v0.5.0) -- traces source-to-sink data flow
- Language support: Rust, Go, Java
- Web dashboard (SaaS)
- REST API (Scan-as-a-Service)
See the full ROADMAP.md.
Contributing
See CONTRIBUTING.md. Bug reports and feature requests welcome.
Security
See SECURITY.md. Report vulnerabilities privately -- do not open public issues.
License
MIT -- see LICENSE.
Built by Dockfix Labs. Built for the AI agent era.
AgentGuard Ecosystem
AgentGuard is the core security scanner. Companion tools:
| Tool | Purpose | Install |
|---|---|---|
| agentguard | AI agent code security scanner | pip install dfx-agentguard |
| mcp-scanner | MCP server security audit | pip install dfx-mcp-scanner |
| agentguard-app | GitHub App for PR reviews | Install from Marketplace |
| agentguard-vscode | VS Code inline diagnostics | Install from VS Code |
| agentguard-benchmark | Detection benchmark suite | git clone |
| agentguard-demo | Live demo with Code Scanning | git clone |
19 detection rules | 102 tests | 50 benchmark samples | OWASP ASI Top 10 GitHub Action: dockfixlabs/agentguard@v1
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file dfx_agentguard-0.7.2.tar.gz.
File metadata
- Download URL: dfx_agentguard-0.7.2.tar.gz
- Upload date:
- Size: 70.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9194e714143ea25a264df3248c25969241804c6f7233f29fcee810ee528808b1
|
|
| MD5 |
3bdc1e1f30e8611e0aa6dbf03bed3ce8
|
|
| BLAKE2b-256 |
f6744601954cc9729cc6ea20aae2f7c212cd4e557c491cbbd5b23ae7a286dbd6
|
File details
Details for the file dfx_agentguard-0.7.2-py3-none-any.whl.
File metadata
- Download URL: dfx_agentguard-0.7.2-py3-none-any.whl
- Upload date:
- Size: 89.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3c8e3ff1e41feae4fe0804443bc60cb6ae5ebdf931b9b128d575a02728221f11
|
|
| MD5 |
78b128930a64b49db43474827057722b
|
|
| BLAKE2b-256 |
458ac58c64f262b4e411fa1ac147102f34e6c437abad4b03ddd4da7e491872f4
|