AgentGuard
Inter-agent security firewall for multi-agent AI systems (LangChain, LangGraph, CrewAI, AutoGen).
PyPI: pip install inter-agent-guard · Import / CLI: agentguard
Docs: inter-agent-guard.readthedocs.io · Blog post · Demo
Docs not loading yet? Import the repo on Read the Docs once — see docs/READTHEDOCS_SETUP.md. Until then: quickstart on GitHub.
AgentGuard intercepts every message between agents and enforces three runtime controls:
- Message Inspector — Aho-Corasick rule filter + DeBERTa ML scorer + consistency check
- Trust Verifier — Ephemeral Ed25519 signing via PyNaCl
- Capability Enforcer — YAML manifests with JSON Schema validation and monotonic attenuation
Quick start
# Python 3.11 or 3.12
pip install "inter-agent-guard[all,otel]"
# ONNX weights are not in the wheel (~164 MB INT8) — from a clone:
python scripts/download_release_model.py
# or: download risk_scorer.onnx + model.sha256 from GitHub Releases into agentguard/models/
agentguard status
agentguard check-manifest manifests/comms_agent.yaml
agentguard inspect -m "Summarise public pricing data from filings."
Note: The PyPI project is
inter-agent-guardbecause bareagentguardcollides with existingagent-guardunder PyPI’s name rules. The Python import and CLI remainagentguard.
from agentguard import AgentGuard, CapabilityManifest
guard = AgentGuard(
risk_threshold=0.85,
task_objective="Analyse Q3 competitor pricing",
audit_log_path="./audit.jsonl",
# Set True in production after installing the ONNX model
require_ml_model=True,
)
guard.register_agent(
"research-agent",
CapabilityManifest.from_yaml("manifests/research_agent.yaml"),
)
secured_graph = guard.wrap(my_langgraph_graph)
Without the ONNX model, rule filtering and trust attestation still run; ML scoring is inactive.
Framework adapters — which to use
| Integration | Production readiness | Notes |
|---|---|---|
LangChain AgentGuardMiddleware |
Recommended | Official create_agent middleware API |
Direct inspect_* / wrap_mcp_tool |
Recommended | Framework-agnostic; full control |
guard.wrap(langgraph_graph) |
Supported | Patches compiled LangGraph nodes |
| CrewAI / AutoGen adapters | Best-effort | Monkey-patch private APIs; emit a UserWarning; mock-tested only |
LangChain agents (official middleware)
AgentGuard plugs into LangChain 1.0's create_agent as standard agent middleware — no monkey-patching, sync and async:
pip install "inter-agent-guard[langchain]"
from langchain.agents import create_agent
from agentguard import AgentGuard
from agentguard.adapters.langchain import AgentGuardMiddleware
guard = AgentGuard(task_objective="Analyse Q3 competitor pricing")
agent = create_agent(
model="gpt-5.5",
tools=[fetch_page, search],
middleware=[AgentGuardMiddleware(guard, agent_id="researcher")],
)
On every run the middleware:
- Scans user input before the first model call (
before_agent) - Inspects every tool output for indirect prompt injection / MCP poisoning before the model sees it (
wrap_tool_call) - Enforces capability manifests before tools execute (register one under
agent_id)
Flagged content is replaced with a safe notice by default (on_violation="replace"), or raises AgentGuardException (on_violation="raise"). mode="monitor" audits without blocking. Try it offline:
python examples/langchain_middleware_example.py
Latency and deployment modes
CPU ONNX P95 is ~3.4 s on holdout (design target was 15 ms). Choose a mode that fits your budget:
| Mode | How | When |
|---|---|---|
| Rules-only | require_ml_model=False (no ONNX) |
Lowest latency; patterns + capability + trust |
| Monitor | mode="monitor" |
Shadow deploy; audit without blocking |
| Enforce + ML (CPU) | require_ml_model=True |
Highest detection; accept ~3 s P95 |
| Enforce + ML (GPU) | Install onnxruntime-gpu |
Lower ML latency when CUDA is available |
| Async / selective hops | Rules on hot path; ML off-path | High-frequency graphs |
Full guide: Latency / deployment modes (source).
Production setup
-
Install the ML model (required for enforce-mode ML scoring):
python scripts/download_release_model.py python scripts/verify_model.py
py -3.12 scripts\download_release_model.py py -3.12 scripts\verify_model.py
Or copy artifacts you already have:
./scripts/install_model.sh ./path/to/model/dir # PowerShell: .\scripts\install_model.ps1 -SourceDir .\path\to\model\dir
Sources: GitHub Releases v1.2.0, local training, or Kaggle (
.\scripts\download_kaggle_model.ps1). -
Confirm health:
agentguard status -
Optional — benchmark on holdout (v1.0 source of truth):
.\scripts\run_benchmark_evaluation.ps1 -Holdout -RequireModel py -3.12 scripts/check_v1_gates.py --allow-cpu-latency
-
Run secured demo:
poetry run python examples/secured_pipeline/pipeline.py
Novel v1.0 corpus is on Hugging Face. To regenerate locally, see docs/ANTHROPIC_DATASET_RUNBOOK.md.
Trust attestation (envelope signatures)
Inter-agent hops require a recipient-bound signature (inter-agent-guard ≥ 1.1.0):
payload = b"Research summary ready for internal report."
sig = guard.sign_payload("researcher", payload, recipient_id="writer")
decision = guard.inspect_message(
"researcher", "writer", payload.decode(), payload, signature=sig,
)
Use inspect_content(...) for unsigned boundaries (user input, framework hooks).
Persist audits with inspect --audit-log ./audit.jsonl, then agentguard verify.
CLI
agentguard version
agentguard status [--json]
agentguard check-manifest manifests/comms_agent.yaml [--json]
agentguard inspect -m "message text" [--audit-log ./audit.jsonl] [--json]
agentguard verify ./audit.jsonl [--json]
Docker
Core runtime image (firewall + OTEL; LangGraph/CrewAI/AutoGen installed separately in app images):
docker build -t agentguard .
docker run --rm agentguard
docker run --rm -v "%CD%\audit.jsonl:/data/audit.jsonl" agentguard verify /data/audit.jsonl
For framework adapters in your own Dockerfile: pip install "inter-agent-guard[all,otel]".
Optional OpenTelemetry export (requires pip install "inter-agent-guard[otel]"):
guard = AgentGuard(enable_otel_export=True, audit_log_path="./audit.jsonl")
Set OTEL_EXPORTER_OTLP_ENDPOINT to auto-configure the OTLP exporter.
Capability enforcement
Manifests declare tools, data sources, endpoints, token limits, and delegation. At runtime:
| API | Enforces |
|---|---|
check_tool_call(agent, tool, endpoint=...) |
permitted_tools, forbidden_tools, optional permitted_endpoints |
check_endpoint(agent, url) |
external_contact + permitted_endpoints |
check_data_source(agent, source) |
allowed_data_sources |
check_output_tokens(agent, n) |
max_output_tokens |
register_delegated_agent(...) |
can_spawn_agents, max_delegation_depth, monotonic attenuation |
See example manifests under manifests/ (including comms_agent.yaml with endpoint allowlists).
Examples
# Vulnerable baseline (100% attack success)
poetry run python examples/vulnerable_pipeline/pipeline.py
# AgentGuard-protected version
poetry run python examples/secured_pipeline/pipeline.py
# MCP poisoning, CrewAI, AutoGen
poetry run python examples/mcp_poisoning_demo.py
poetry run python examples/crewai_example.py
poetry run python examples/autogen_example.py
Benchmark
AgentGuard ships with a 6,200-example inter-agent benchmark (1,200 adversarial + 5,000 benign).
Published on Hugging Face: Nizba/agentguard-benchmark-v1 (Anthropic Batch, anthropic_batch_v1).
Build dataset locally (zero cost, optional)
.\scripts\run_public_dataset_build.ps1
Sources: InjecAgent (GitHub) + inter-agent framing templates + pipeline-style benign messages.
Run evaluation
Holdout (uncontaminated — use for v1.0 gating):
.\scripts\run_benchmark_evaluation.ps1 -Holdout -RequireModel
Results: benchmarks/results/holdout_report.md
Full corpus (may overlap training data — not a ship gate):
.\scripts\run_benchmark_evaluation.ps1 -RequireModel
Results: benchmarks/results/report.md
Latest results (v1.2.0)
Quote the external table, not the in-house holdout. On
deepset/prompt-injections test (116 rows; train split used in training),
Rules + ML at risk > 0.85 vs a length ruler that reads nothing:
| Detector | Detection | FPR | Balanced accuracy |
|---|---|---|---|
length > 430 |
8.3% | 0.0% | 54.2% |
| Rules + ML | 90.0% | 0.0% | 95.0% |
In-house holdout (same Claude generator as training — regression only): 92.0% detection / 0.3% FPR, P95 ~3.3 s CPU. The v1 99.4% figure is withdrawn (that scorer classified on message length). Full caveats: docs/KNOWN_LIMITATIONS.md.
Package version: 1.2.0. ONNX assets: GitHub release v1.2.0. CPU ML P95 does not meet the original 15 ms design target — use rules-only, GPU, or async for high-QPS (see latency guide).
.\scripts\run_benchmark_evaluation.ps1 -Holdout -RequireModel
py -3.12 scripts/check_v1_gates.py --allow-cpu-latency
Reproduce with the HF corpus or local benchmarks/dataset/*.jsonl after a verified model install. See docs/V1_ROADMAP.md.
vs Microsoft Agent Governance Toolkit
Feature matrix and shared-dataset methodology: docs/MICROSOFT_TOOLKIT_COMPARISON.md.
py -3.12 scripts\run_toolkit_comparison.py
Training (Kaggle GPU)
.\scripts\push_kaggle_kernel.ps1 # uploads code dataset + pushes notebook
Open kernel on Kaggle → GPU T4 x2 + Internet → Run All. Copy agentguard/models/* from Output tab.
See training/kaggle_notebook.ipynb.
Documentation
- Read the Docs — quickstart, latency, API (import repo once: setup guide)
- Technical blog
- Microsoft toolkit comparison
- CONTRIBUTING.md
- REQUIREMENTS.md
- DESIGN.md
- Known limitations
- Release notes v1.2.0
- Release notes v1.1.0
- Release notes v1.0.0
- Launch checklist
- Hugging Face dataset card
Build docs locally:
poetry install --with docs
sphinx-build -b html docs/source docs/_build/html
# open docs/_build/html/index.html
License
Apache-2.0 — see LICENSE.
Metadata
Release files for inter-agent-guard 1.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| inter_agent_guard-1.2.0.tar.gz | 3.2 MB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| inter_agent_guard-1.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 6.4 MB
Release files / inter_agent_guard-1.2.0.tar.gz
| Download URL | inter_agent_guard-1.2.0.tar.gz |
|---|---|
| Size | 3.2 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fc23a642c9d33c337e823dab1852d90f334d8e0c67dd89dd70c03a91980afe68
|
|
BLAKE2b-256 checksum How to use checksums |
a7e464185501f9e5bd553da09423620541e1a3ab272d8a40769e97d0a93f52df
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.0
|
Release files / inter_agent_guard-1.2.0-py3-none-any.whl
| Download URL | inter_agent_guard-1.2.0-py3-none-any.whl |
|---|---|
| Size | 3.2 MB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f6bc20599b24640867ecf16a8b6e105e1df2e5ba55be6331c62165a665b57db3
|
|
BLAKE2b-256 checksum How to use checksums |
87f3f42c6005b6013d5193a90b61a4700f5d7371903cdfd374546d7ded974652
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.0
|