Runtime security for AI agents

Give your agents freedom.
Keep control.

Check every command and tool call before it runs. Stop risky actions locally, and give your team a clear record of what happened.

Open source. No signup to install. Your tools, your workflow.

Works with the agents and tools your team already uses
Claude CodeCursorWindsurfCodex CLIGemini CLIOpenClawMCPLangChain

Every action. In view.

Example activity
Policy modeEnforce
EvaluationOn device
Audit trailConnected
Recent decisions Shell commands
Command Agent Decision
git status Claude Code Allowed
cat ~/.ssh/id_rsa Cursor Blocked
chmod -R 777 /var/www Claude Code Audited
From a local decision to a shared audit trail.Explore the interactive showcase →
Local firstDecisions on your machine.
No model calls.
Almost 4,000 rulesA growing security library.
Shell commands and MCP tools.
8 frameworksSecurity and governance, connected.SOC 2 · ISO 42001 · EU AI Act + more
How it works

Move fast. Keep a clear view.

AgentShield checks actions on the machine. Agent Lens brings the decisions together for your team.

01 · Gate

Stop it before it runs

Destructive commands, credential reads, pipe-to-shell, exfiltration, poisoned tools. Decided locally, rule named.

02 · Observe

One audit trail

Every decision from every machine. Start in audit-only mode and see what would have been blocked.

03 · Prove

Evidence you can use

Each rule maps to controls in the frameworks you're audited against. Export it.

Try it

See the decision.
Understand the why.

Paste a shell command or choose an example. AgentShield checks it against the community rules and explains its decision. No commands are executed.

Shell commandCommunity rules
The verdict, the rule that fired, and why.
For security teams

One record of what your agents did.

  • Fleet. Every agent, its rules, its last check-in.
  • Policy. Enable a framework; rules reach every machine.
  • Audit trail. Hash-chained, exportable.
  • Posture. Which controls real activity exercises.
Open the showcase Handbook
Rules attesting SOC 2 Type IIExample evidence
Rule Decision Fires Control
sec-block-git-log-credential-mining BLOCK 59 CC6.1 · CC6.7
ai-mcp-tool-description-poisoning BLOCK 51 CC6.8 · CC7.2
sec-df-block-cred-to-network BLOCK 40 CC6.7
ai-llm-output-code-eval-python AUDIT 52 CC7.2 · CC8.1
ne-block-dns-exfil-backtick BLOCK 21 CC6.7
The problem

The agent has your keys.

Agents inherit your permissions. Their actions deserve the same visibility and controls as the rest of your stack.

No exploit required

One poisoned tool description or README is enough to send a private key to a stranger. How →

Wrong layer

EDR sees a trusted shell. The firewall sees HTTPS. AgentShield checks the command before it becomes an action.

No answer for the auditor

"How do you control what your AI agents can do? Show me the record." Most teams can't. What that looks like →

Install to enforced

A few commands.
A clearer boundary.

Four commands on a laptop, one switch in the dashboard.

Read the setup guide →
Step 1

Install AgentShield

One Homebrew command. Prebuilt binary, macOS and Linux.

$ brew tap AI-AgentLens/tap && brew install --cask agentshield
Step 2

Hook your agent

Claude Code, Cursor, Windsurf, Codex CLI, Gemini CLI, OpenClaw, or the MCP proxy.

$ agentshield setup claude-code
Step 3

Connect your team

Device-code sign-in. Policy and rule packs pull down; decisions stream up.

$ agentshield login
Step 4

Watch for a week, then enforce

Read what would have been blocked. Then flip the organisation to enforce.

$ agentshield scan
Built with clear boundaries

Know what you’re installing.

Checks, without execution.

The agent asks "may I?". We answer.

Evaluation stays local.

No model calls or telemetry in the local evaluator. Connect to Agent Lens when you want a shared audit trail.

Open about its limits.

We publish our own bypasses. Start here →

Pricing

Start small. Bring your team.

Start with visibility. Add enforcement and longer retention as your team grows.

Free

$0
  • 5 members, 5 agents
  • OWASP LLM Top 10
  • Audit-only mode
  • 7-day retention
Start free

Team

$29per user / month
  • 50 members, 100 agents
  • OWASP, SOC 2, ISO 27001
  • Enforcement, custom rules
  • 90-day retention, reports
Start with Team

Enterprise

Custom
  • Unlimited members and agents
  • Adds GDPR and HIPAA
  • Custom data labels
  • 1-year retention, priority support
Talk to us
Get started

Start with one agent.
Bring the whole team.

Install on your own machine first. Then invite the team. [email protected]

$ brew tap AI-AgentLens/tap && brew install --cask agentshield
$ agentshield setup claude-code # or cursor, windsurf, codex, gemini-cli, openclaw, mcp
Prebuilt binaries. No dependencies.
Download for macOS
macOS 12+ · tar.gz archive
Download for Linux
$