Pre-run skill and server scanning
Checks AI agent skills and MCP servers before an agent loads them, using ATR detection rules to catch known attack patterns such as prompt injection, tool poisoning, and supply-chain threats.
Panguard AI is an AI agent security tool that scans skills and MCP servers for threats before they run and guards agent actions at runtime. It is built for developers, AI vendors, and regulated teams that need local protection and audit-ready evidence.
Panguard AI is an AI agent security product that scans skills and MCP servers for threats before they run, then continues to guard agent actions at runtime. The site positions it as a way for developers and regulated teams to reduce exposure to prompt injection, tool poisoning, malicious MCP content, and related supply-chain risks.
The product is built around ATR, an open rulebook of executable detection rules. The community edition is free, MIT licensed, self-hosted, and described as running offline with zero telemetry. Paid plans add support for proving security in enterprise review workflows, including signed compliance evidence packs and larger deployments.
Checks AI agent skills and MCP servers before an agent loads them, using ATR detection rules to catch known attack patterns such as prompt injection, tool poisoning, and supply-chain threats.
Monitors agent activity at runtime so it can catch and contain hijack attempts after an agent starts executing actions.
Produces signed, audit-ready evidence rather than just a detection result, including PDF and JSON outputs mapped to compliance frameworks.
Runs locally and is described as self-hosted, offline, and zero-telemetry, which supports teams that want on-device protection.
Uses a shared ATR rulebook that is open source and updated through community rules, with rule updates delivered through the Threat Cloud in under 24 hours on the community plan.
Supports a CLI workflow with commands for scanning, auditing, guarding, and checking status.
Run a skill or MCP server through a pre-flight scan before letting an agent use it, so suspicious instructions or package content can be blocked earlier in the workflow.
Keep protection active while an agent is acting, for cases where a clean pre-scan is not enough and runtime behavior still needs containment.
Generate signed evidence and framework mappings for security, audit, or procurement review when a team needs to show how agent risks were checked.
Use the free, self-hosted community edition for individual developers or small teams that want local protection without a hosted service.
Move to the paid founding pilot or enterprise offering when the goal is not only protection but also support, review-ready documentation, and larger deployment needs.
Panguard AI is installed locally with a one-line command and runs offline. The site says it is MIT licensed, self-hosted, and has zero telemetry.
The product is aimed at developers, AI vendors, regulated teams, and enterprises that need to scan AI agent skills or prove security in review processes. The pricing page distinguishes a free community edition from paid offerings for compliance evidence and larger deployments.
The home page says it scans skills and MCP servers before they run, and also guards agent actions at runtime. The product therefore covers both pre-run scanning and runtime protection.
It can produce signed, audit-ready evidence and reports. The site mentions PDF and JSON outputs, SHA-256 and Merkle-tree signing, and evidence packs mapped to compliance frameworks.
The site is conservative about scope: it focuses on skills, MCP servers, and agent actions. It also notes that some capabilities, such as optional LLM second opinion and collective defense, are off by default.
ByteAsk is a terminal-first AI coding agent for C and C++ that edits repositories and verifies changes with the real compiler, debugger, sanitizers, and tests before showing a diff. It offers a free tier plus paid plans, with editor connectors and zero-retention handling described in the source.
Manta AI is an autonomous web app testing tool for teams that want to map application behavior, catch regressions, and generate tests without writing scripts or maintaining selectors. It works from a URL and supports plain-English test flows, run results with screenshots, and scheduled or deployment-triggered checks.
AakarDev AI helps teams manage AI provider access, project-level setups, logs, and analytics from one dashboard. It supports BYOK workflows and lists providers including OpenAI, Google Gemini, Anthropic, Groq, Mistral AI, and Perplexity AI.
Arduino VENTUNO Q is an edge AI computer for AI and robotics applications. It combines AI inference and deterministic control on a single board and is designed to work with Arduino App Lab.
Devin is an AI coding agent and software engineer that helps developers and engineering teams plan and execute complex software tasks. It is available through desktop, cloud, JetBrains, and CLI surfaces, with plans for individuals, teams, and enterprises.
Codex Plugins bundle reusable skills, app integrations, and MCP servers into workflows you can install in the Codex app or use from Codex CLI. They help extend Codex with connected-service tasks, reusable instructions, and shared team workflows.