Skip to main content
Glama

AgentGuard — security checks for AI agents (MCP server)

A free, open-source, single-binary MCP server that gives any AI agent (Claude Desktop, Cursor, Claude Code, …) security checks in the loop:

Tool

What it does

Data source

scan_secrets

Flags hard-coded secrets (API keys, tokens, private keys) in text/code/diffs before the agent commits, logs, or sends them. Runs locally; values are masked.

local (regex + entropy)

check_cve

Whether a specific package version has known CVEs, with severity + fixed version.

OSV.dev (free)

scan_dependencies

Scans a go.mod / package.json / requirements.txt and reports every vulnerable pinned dependency.

OSV.dev (free)

No API key, no account, no telemetry. Everything runs locally except CVE lookups, which hit the free public OSV.dev API.

Install

Pick whichever fits your setup. All three give the same stdio MCP server.

Docker (no Go toolchain needed)

docker run -i --rm ghcr.io/shuaicongxiaomai/agentguard:latest demo

MCP client config (mcpServers block in Claude Desktop / Cursor / Claude Code):

{
  "mcpServers": {
    "agentguard": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "ghcr.io/shuaicongxiaomai/agentguard:latest"]
    }
  }
}

Go install

go install github.com/shuaicongxiaomai/agentguard@latest
{ "mcpServers": { "agentguard": { "command": "agentguard" } } }

Prebuilt binary

Download the archive for your OS/arch from the Releases page, extract it, and point the config command at the absolute path to the binary.

Related MCP server: opzyai

Build from source

go build -o agentguard .          # append .exe on Windows

Three ways to run it

1. demo — see it work, zero config:

agentguard demo

Runs all three tools on sample inputs and prints the results.

2. stdio (default) — local use; the MCP client launches the binary. No port; the client manages its lifecycle. Use any of the configs above, then ask your agent: "scan this for secrets", "is lodash 4.17.20 vulnerable?", "check my package.json for vulnerable deps."

3. serve — Streamable HTTP service on a port (for a hosted/remote server):

agentguard serve :8080          # or set PORT=8080
# health:   GET  http://host:8080/healthz
# MCP URL:  POST http://host:8080/mcp   (clients connect to this URL)

Use stdio for local use; use serve when you want a hosted server users connect to by URL without installing anything.

Notes

  • scan_secrets runs locally and never returns raw secret values — only masked previews.

  • scan_dependencies caps at 200 deps per call and queries OSV concurrently.

  • check_cve / scan_dependencies need network access to OSV.dev; scan_secrets is fully offline.

License

MIT.

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
0dRelease cycle
3Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    B
    maintenance
    Local-first security check for AI coding agents — finds hardcoded secrets, exposed .env files, git-history leaks and vulnerable dependencies (OSV), entirely on your machine. Ask your agent "is this safe to ship?" and get a Launch Readiness score with a fix for every finding.
    Last updated
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    Provides local, dependency-free security scanning tools for LLM configurations, prompts, RAG sources, and more, enabling AI coding agents to detect prompt injections and other vulnerabilities without external network access.
    Last updated
    MIT

View all related MCP servers

Related MCP Connectors

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.

  • Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/shuaicongxiaomai/agentguard'

If you have feedback or need assistance with the MCP directory API, please join our Discord server