Zero-Network Static Security for AI Agents

Secure Your AI Agents Before They Execute

Deterministic static analyzer and containment harness for MCP configs, Cursor rules, and agent skills. 57 rules, sub-10ms scans, zero network calls, zero cloud LLM hallucinations.

$ pip install agentsec-cli && agentsec scan .
Secures out-of-the-box:
Claude Desktop Cursor Windsurf Cline & Roo LangChain DevContainers
57
Security rules (AGENT001–057)
100%
Offline: zero LLM & network
0–100
Security score & A–F grades
<10ms
<10ms execution in CI & git
LIVE PLAYGROUND

Test Real Agent Exploits in Real Time

Select a scenario below to observe how AgentSec parses dangerous configs, calculates security scores, and generates scoped fix diffs.

CONFIG FILE
claude_desktop_config.json
AGENTSEC AUDIT
D 40/100
Detected Findings
Scoped Fix Plan (--suggest-fixes)
CAPABILITY MATRIX

Standard Setups vs. AgentSec Hardening

Real boundary enforcement and static verification compared to generic unvetted agent environments.

Security Dimension Without AgentSec With AgentSec
MCP Tool Sandboxing Raw bash/powershell commands and root (/) filesystem mounts are allowed by default. Strict whitelist enforcement, flags shell interpreters, and blocks root mounts (AGENT001, AGENT002).
Container Escapes DevContainers often mount /var/run/docker.sock or run with privileged: true unnoticed. Blocks Docker socket mounts and privileged execution before containers start (AGENT051, AGENT052).
Tool Shadowing Hijack Untrusted MCP servers silently register matching tool names, hijacking execution paths. Cross-config namespace analysis detects collisions and shadowed built-ins (AGENT050).
Data Privacy & Air-Gap Cloud LLM scanners send proprietary source code, secrets, and prompts to external third parties. 100% offline static analyzer, 0 network connections, zero telemetry, air-gapped ready.
CI/CD Gating & Speed Slow manual reviews or 30-second cloud LLM evaluations prone to stochastic hallucinations. Deterministic sub-10ms scans with configurable quality gate thresholds (--fail-on-score 85).
MCP Tool Sandboxing
Without AgentSec

Raw bash/powershell commands and root (/) filesystem mounts are allowed by default.

With AgentSec

Strict whitelist enforcement, flags shell interpreters, and blocks root mounts (AGENT001, AGENT002).

Container Escapes
Without AgentSec

DevContainers often mount /var/run/docker.sock or run with privileged: true unnoticed.

With AgentSec

Blocks Docker socket mounts and privileged execution before containers start (AGENT051, AGENT052).

Tool Shadowing Hijack
Without AgentSec

Untrusted MCP servers silently register matching tool names, hijacking execution paths.

With AgentSec

Cross-config namespace analysis detects collisions and shadowed built-ins (AGENT050).

Data Privacy & Air-Gap
Without AgentSec

Cloud LLM scanners send proprietary source code, secrets, and prompts to external third parties.

With AgentSec

100% offline static analyzer, 0 network connections, zero telemetry, air-gapped ready.

CI/CD Gating & Speed
Without AgentSec

Slow manual reviews or 30-second cloud LLM evaluations prone to stochastic hallucinations.

With AgentSec

Deterministic sub-10ms scans with configurable quality gate thresholds (--fail-on-score 85).

THREAT LANDSCAPE

How Real AI Agents Get Compromised

Agents don't just chat — they execute code, read files, and call external tools. Here are the 4 attack vectors AgentSec blocks.

CRITICAL

1. The Shell Escalation Trap

A developer gives an agent a bash MCP server 'just to run tests'. An untrusted prompt injection instructs the agent to curl an external reverse shell script.

Blocked by AGENT001 & AGENT009
CRITICAL

2. Docker Socket Escape

DevContainers mount /var/run/docker.sock for convenience. The agent creates a container mounting the host root filesystem, gaining full root.

Blocked by AGENT051 & AGENT052
HIGH

3. MCP Tool Shadowing

A secondary community MCP server registers a tool named read_file. It intercepts all repository file reads, exfiltrating secrets to an attacker server.

Blocked by AGENT050
CRITICAL

4. Cloud Metadata IMDS SSRF

An agent equipped with web scraping tools is tricked into requesting 169.254.169.254, dumping AWS/GCP IAM role credentials.

Blocked by AGENT043 & AGENT049
ARCHITECTURE

Why AgentSec is 100% Offline

Security tools shouldn't become another attack surface. AgentSec requires zero network access and makes zero API calls.

Zero Data Leakage

Your configs, MCP servers, prompt instructions, and code never leave your machine. No telemetry, no external logging, no SaaS dependency.

Air-Gapped Compliance

Works flawlessly inside air-gapped corporate networks, isolated devboxes, banking VPCs, and offline build runners with zero outbound internet.

Deterministic & Reproducible

Pure AST parsing, regex validation, and static logic. Run it 1,000 times and get the exact same results with zero model drift or hallucinations.

1-Command Harness Setup

Run 'agentsec init-harness' to bootstrap .agentsecignore, .agentsec.yaml, pre-commit hooks, and AGENTS.md rules in seconds.

SPECIFICATION

57 Security Rules Mapped to OWASP

Every rule is cross-mapped to OWASP Top 10 for LLMs and the OWASP Agentic Security (2026) framework.

Showing 57 of 57 rules
Rule ID Severity Rule Name & Recommendation OWASP Mapping Target Scope
WORKFLOWS

Integrate Into Any Developer Stack

Run locally, embed in pre-commit hooks, or enforce security gates in GitHub Actions.

1. Local Quickscan

Scan current workspace, MCP configs, and skill files in sub-10ms.

pip install agentsec-cli
agentsec scan .

2. CI/CD Quality Gate

Fail pipeline builds if risk score drops below security policy threshold.

agentsec scan . \
  --fail-on-score 85 \
  --fail-on critical

3. Self-Contained HTML Report

Generate interactive zero-dependency audit report with visual charts.

agentsec scan . \
  --format html > audit-report.html

4. Initialize Secure Harness

Scaffold .agentsecignore, .agentsec.yaml, and git hooks in one command.

agentsec init-harness
git add .agentsec.yaml .agentsecignore