Skip to main content

FAQ

Does this slow my agent down?

No. A decision takes under 30 milliseconds on the machine, with no network round trip. Agents already spend far longer than that thinking.

Will it block my normal work?

New installs are audit-only: nothing is blocked until you say so. When you turn enforcement on, the rules that fire are the ones you reviewed. False positives happen; each rule can be disabled or allow-listed locally, and we treat a false positive as a bug.

Which agents are supported?

Claude Code, Cursor, Windsurf, Codex CLI, Gemini CLI and OpenClaw have native hooks. Any MCP server can be wrapped by the proxy. LangChain and custom agents can call the CLI. See Agent and IDE integration.

Do I need the cloud?

No. AgentShield works standalone with the embedded community rules and your own YAML, and writes its audit log locally. The cloud adds shared policy, a central audit trail, premium rule packs and compliance evidence.

Can the model vendor's own safety features replace this?

They help, and they are improving. But they are the model judging the model's own command, inside the vendor's agent only. A control an auditor accepts is deterministic, sits outside the model, covers every agent you run, and produces a record you own.

Is it really open source?

AgentShield is Apache 2.0. The analyzer, the community rule packs, the hooks and the MCP proxy are all in the public repository. The cloud platform and the premium rule packs are commercial.

What does it cost?

AgentShield is free forever. The free organisation tier gives a small team the audit trail. Paid tiers add enforcement, more frameworks and reports. See pricing.

How do I get help?

Email [email protected]. Bypasses and false positives get the fastest replies.