agentguard

A security review and design assistant for applications that use AI language models and agents. It checks areas such as tool calls, memory, retrieval from documents, MCP connections, and multiple cooperating agents, using OWASP and CWE security categories.

In plain words
What is it for?
For auditing an existing AI-agent project, scanning it quickly, or creating a security plan for a new one.
Why use it?
It helps identify security risks in AI-based software and gives design advice before coding. OWASP is a security guidance organisation, while CWE is a catalogue of common software weaknesses.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/ethonik/agentguard/agentguard
Any agent
npx skills add Ethonik/agentguard --skill agentguard
Clone the repo
git clone --depth 1 https://github.com/Ethonik/agentguard

Made for: Claude Code, Codex.

Per session 189 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,842 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00189 $0.02842
Opus 5 $0.00095 $0.01421
Sonnet 5 $0.00038 $0.00568
Haiku 4.5 $0.00019 $0.00284

Measured 2d ago against content hash 82c989b7d27b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

agentguard scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 2 executable files (scripts/detect_stack.py, scripts/scan_agentic_patterns.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/agentguard/SKILL.md · 178 lines

How it starts

The opening of the file, as written. The whole thing — 178 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/agentguard

Skill de seguridad para aplicaciones agénticas: cualquier herramienta que use LLMs y agentes como componentes (llamadas a modelos, tool-calling, memoria/RAG, MCP, orquestación multi-agente). Hace dos cosas:

  • review — audita código/diseño existente y produce un informe de hallazgos mapeados a OWASP.
  • design — asesora antes de codificar: threat model + checklist seguro-por-diseño.

Todo se ancla a tres marcos (los IDs y términos van en inglés):

  • OWASP Top 10 for Agentic Applications 2026ASI01ASI10.
  • OWASP Top 10 for LLM Applications 2025LLM01LLM10.
  • CWE (MITRE) — clase de debilidad de cada hallazgo (CWE-1427, CWE-1426, CWE-78, …), con las mitigaciones oficiales de MITRE. Ver references/cwe-agentic-llm-2026.md.

Uso

/agentguard                      # modo auto: detecta contexto y elige review o design
/agentguard review               # audita el directorio actual
/agentguard review <path>        # audita un path/proyecto específico
/agentguard review --quick       # solo scripts (detect + scan), sin lectura profunda
/agentguard design               # asesoría de diseño interactiva
/agentguard design "<idea>"      # asesoría a partir de una descripción de arquitectura
/agentguard explain ASI06        # explica una amenaza concreta (ASI0x, LLM0x o CWE-nnnn)
/agentguard --help               # imprime esta sección de Uso y termina

Qué debes hacer al invocarte

Si el usuario invoca /agentguard --help o -h (sin otros argumentos): imprime el bloque ## Uso de arriba verbatim y termina. No escanees, no ejecutes scripts.

Si el primer argumento es explain seguido de un ID (ASI0x / LLM0x / CWE-nnnn): lee la entrada correspondiente en references/owasp-agentic-asi-2026.md, references/owasp-llm-top10-2025.md o references/cwe-agentic-llm-2026.md y explícala en español (qué es, señales, mitigaciones, ejemplo real / CWE relacionados). Termina.

Ruta de scripts: los scripts viven junto a este archivo, en scripts/. Resuélvelos relativo a la ubicación de SKILL.md (p. ej. <skill_dir>/scripts/detect_stack.py). Corren con python3 sin dependencias externas.

Read the full file on GitHub · 178 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 178 lines · 189 tokens per session scan A 82c989b7d27b

Subscribe to this mod's changes

agentguard is a skill published in the GitHub repository Ethonik/agentguard (2 stars, last pushed 1mo ago), licensed MIT. It adds 189 tokens to every session and 2,842 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.