Back to tools

agentshield

An open-source security scanner for teams building MCP or AI agent apps, producing SARIF security findings via offline static analysis for GitHub Code Scanning workflows.

Tool categories
Developer toolsEnterprise
Tool links

Tool overview

Based on the available evidence, agentshield is best judged as an early open-source security scanner worth watching for shift-left AI agent security, but not yet something with strong independent validation. Nearly all evidence comes from the project’s own GitHub listing, which supports what it claims to do more than how well it works in practice.

Its practical role is closer to a specialized SAST tool for MCP and agent stacks: it runs offline, is implemented in Rust, targets frameworks and environments such as Claude, Cursor, OpenAI Agents, LangGraph, and CrewAI, and emits SARIF for GitHub Code Scanning. It is not a runtime firewall, not a managed security service, and not a general-purpose coding assistant; a better analogy is an open-source lint/SAST layer for AI agent security checks.

On cost and adoption friction, the evidence only supports that it is open source. There is no supported pricing, hosted plan, or API fee information in the evidence, so the cautious read is that license cost may be low while implementation cost depends on your CI setup, GitHub security workflow, and tolerance for false positives.

Related social content

No related content yet

This tool does not have related social references to display yet.