Give your agents freedom.
Keep control.
Check every command and tool call before it runs. Stop risky actions locally, and give your team a clear record of what happened.
Open source. No signup to install. Your tools, your workflow.
Every action. In view.
Example activity| Command | Agent | Decision |
|---|---|---|
git status |
Claude Code | Allowed |
cat ~/.ssh/id_rsa |
Cursor | Blocked |
chmod -R 777 /var/www |
Claude Code | Audited |
No model calls.
Shell commands and MCP tools.
Move fast. Keep a clear view.
AgentShield checks actions on the machine. Agent Lens brings the decisions together for your team.
Stop it before it runs
Destructive commands, credential reads, pipe-to-shell, exfiltration, poisoned tools. Decided locally, rule named.
One audit trail
Every decision from every machine. Start in audit-only mode and see what would have been blocked.
Evidence you can use
Each rule maps to controls in the frameworks you're audited against. Export it.
See the decision.
Understand the why.
Paste a shell command or choose an example. AgentShield checks it against the community rules and explains its decision. No commands are executed.
One record of what your agents did.
- Fleet. Every agent, its rules, its last check-in.
- Policy. Enable a framework; rules reach every machine.
- Audit trail. Hash-chained, exportable.
- Posture. Which controls real activity exercises.
| Rule | Decision | Fires | Control |
|---|---|---|---|
| sec-block-git-log-credential-mining | BLOCK | 59 | CC6.1 · CC6.7 |
| ai-mcp-tool-description-poisoning | BLOCK | 51 | CC6.8 · CC7.2 |
| sec-df-block-cred-to-network | BLOCK | 40 | CC6.7 |
| ai-llm-output-code-eval-python | AUDIT | 52 | CC7.2 · CC8.1 |
| ne-block-dns-exfil-backtick | BLOCK | 21 | CC6.7 |
The agent has your keys.
Agents inherit your permissions. Their actions deserve the same visibility and controls as the rest of your stack.
No exploit required
One poisoned tool description or README is enough to send a private key to a stranger. How →
Wrong layer
EDR sees a trusted shell. The firewall sees HTTPS. AgentShield checks the command before it becomes an action.
No answer for the auditor
"How do you control what your AI agents can do? Show me the record." Most teams can't. What that looks like →
A few commands.
A clearer boundary.
Four commands on a laptop, one switch in the dashboard.
Read the setup guide →Install AgentShield
One Homebrew command. Prebuilt binary, macOS and Linux.
Hook your agent
Claude Code, Cursor, Windsurf, Codex CLI, Gemini CLI, OpenClaw, or the MCP proxy.
Connect your team
Device-code sign-in. Policy and rule packs pull down; decisions stream up.
Watch for a week, then enforce
Read what would have been blocked. Then flip the organisation to enforce.
Know what you’re installing.
Checks, without execution.
The agent asks "may I?". We answer.
Evaluation stays local.
No model calls or telemetry in the local evaluator. Connect to Agent Lens when you want a shared audit trail.
Open about its limits.
We publish our own bypasses. Start here →
Start small. Bring your team.
Start with visibility. Add enforcement and longer retention as your team grows.
Team
- 50 members, 100 agents
- OWASP, SOC 2, ISO 27001
- Enforcement, custom rules
- 90-day retention, reports
Enterprise
- Unlimited members and agents
- Adds GDPR and HIPAA
- Custom data labels
- 1-year retention, priority support
Start with one agent.
Bring the whole team.
Install on your own machine first. Then invite the team. [email protected]