Pre-execution skill and MCP scanning
Scans AI agent skills and MCP servers before the agent loads them, using ATR rules to detect prompt injection, tool poisoning, malicious MCP content, and supply-chain threats.
Panguard AI is an open-source security platform for AI agents that scans skills and MCP servers before they run and protects agent actions at runtime.
Panguard AI is an open-source security platform for AI agents. Its core job is to scan skills and MCP servers before they run, then protect agent actions at runtime using the ATR rulebook, which the site positions as an agent-era counterpart to shared detection standards such as CVE and Sigma.
The product is aimed at developers and regulated teams that need practical controls and evidence, not just alerts. The site says the community edition is MIT-licensed, self-hosted, zero-telemetry, and free forever, while paid plans add signed compliance evidence reporting, enterprise deployment options, and support for on-prem, VPC, and airgapped environments.
Scans AI agent skills and MCP servers before the agent loads them, using ATR rules to detect prompt injection, tool poisoning, malicious MCP content, and supply-chain threats.
Runs protections at runtime as agents act, so detections are not limited to a one-time preflight review.
Describes an optional deceive-and-respond layer in the pricing page, alongside protect and detect, for broader security workflows.
Produces signed, audit-ready evidence in PDF and JSON, with SHA-256 and Merkle-tree signing and framework mappings for compliance review.
Uses an ATR rulebook that is local-first and deterministic, with rule updates distributed through the Threat Cloud and community rule contributions.
Provides command-line workflows such as scan, audit, guard, and status, with one-command installation and self-hosted operation.
Before deploying a skill or MCP server, a developer can scan it for prompt injection, tool poisoning, or other rule-based threats and review the findings before the agent loads it.
Teams that want continuous protection can run the guard and status workflows to monitor agent activity after rollout instead of relying only on one-time audits.
Regulated organizations can use the signed PDF or JSON outputs, framework mappings, and evidence packs to support security reviews and compliance discussions.
Organizations that prefer local control can use the self-hosted community edition, which the site says runs offline and has zero telemetry.
Enterprise teams can use the on-prem, VPC, or airgap options and connect the platform to SSO and SIEM workflows for larger deployments.
Panguard AI is built to scan AI agent skills and MCP servers before they run, then protect agent actions at runtime. The source also describes a free open-source community edition and a paid Enterprise add-on for teams that need signed compliance evidence reporting.
The pricing page says Community is available today at $0 forever, with MIT-licensed open-source access. Paid offerings include a $25K one-time Founding Pilot and sales-led Enterprise plans starting at $150K+ per year.
The site says you can install with one command and that the Community edition is self-hosted, zero telemetry, and runs offline. The pricing page also lists pga CLI commands for scan, audit, guard, and status.
The product pages say Panguard AI can scan skills and MCP servers, protect agent actions at runtime, and emit signed, audit-ready evidence. The pricing and enterprise pages also describe PDF and JSON outputs, SHA-256 and Merkle-tree signing, and compliance mapping.
The pricing page says Enterprise & up includes on-prem, airgap, SSO, and SIEM support, while the enterprise specification adds SAML SSO, SCIM, SIEM webhook, and audit-log export. Community is self-hosted and runs on-device.
Kastra authorization infrastructure for AI systems checks prompts, tool calls, shell commands, API requests, and browser actions before execution.
Orca is an Agent Development Environment for shipping with coding agents, running multiple CLI agents in parallel across isolated worktrees, with desktop and mobile workflows.
AI Magicx is a unified AI workspace for chat, image, video, voice, music, email and developer tasks, helping teams and creators manage multiple models in one place.
Paper is a design tool that connects canvas, code, and AI agents so teams can create, share, and ship work in one workflow. Includes desktop app and MCP access.
blop is a QA agent that writes browser tests as code in your repo, runs them in CI, clusters repeated failures, and can open PRs to fix broken tests.
RLAMA is a local AI platform for building RAG systems and intelligent agents on macOS, Linux, and Windows, with HTTP API support.