AgentShield
aiconnai/agentshield
Offline Rust scanner for risky behavior in MCP servers and agent tools, with a Hermes Agent adapter
AgentShield is an offline Rust security scanner for tool-enabled AI agents, with native adapters for MCP servers, OpenClaw skills and Hermes Agent configs. It flags risks such as command injection, credential exfiltration and SSRF before an agent can call the tools.
What AgentShield does
AgentShield normalizes 11 framework and client families into one intermediate representation: MCP, OpenClaw, Hermes Agent, CrewAI, LangChain and LangGraph, GPT Actions, Cursor Rules, Vercel AI SDK, AutoGen, LlamaIndex and Semantic Kernel. It applies 37 built-in contextual rules plus a declarative YAML rule engine read from .agentshield/rules, and tracks untrusted input across functions in Python and TypeScript through to execution sinks.
It runs as a CLI, GitHub Action, VS Code extension or Rust library, entirely offline, and emits console, JSON, SARIF and standalone HTML reports. agentshield fix applies automatic fixes for unsafe deserializers and unpinned dependencies. A runtime guard acts as a reverse proxy for MCP stdio and HTTP/SSE streams, inspecting tool calls and redacting leaked secrets. The README describes it as a complement to general SAST and secret scanning, not a replacement, and lists release 1.0.1 as General Availability.
Key features
- Adapters for 11 framework families including MCP, OpenClaw and Hermes Agent
- 37 built-in rules plus custom YAML rules
- Cross-function taint analysis for Python and TypeScript
- agentshield fix for unsafe deserializers and unpinned dependencies
- Runtime guard proxy for MCP stdio and HTTP/SSE streams with secret redaction
- SARIF output for GitHub Code Scanning
When to use it
- Scanning an MCP server before adding it to a client configuration
- Checking a Hermes Agent config and tool code for risky patterns in CI
- Reviewing community agent extensions for credential exfiltration or SSRF
Who it is for: Teams that ship or install tool-enabled agent extensions and want an offline pre-release security check.
How it fits with Hermes Agent
Hermes Agent configs are one of the natively supported scan targets, though the tool is a general scanner for many agent frameworks.
FAQ
What is AgentShield?
AgentShield is an offline, Rust-based security scanner for MCP servers and AI agent extensions. It finds command injection, credential theft, SSRF, unsafe file access and similar issues with static analysis.
Does AgentShield work with Hermes Agent?
Yes, Hermes Agent configs are one of its native adapters. They are checked with the same rules AgentShield applies to other frameworks, and the scan runs offline.
Is AgentShield free and open source?
The source is public, but GitHub does not report a standard license identifier. The README links LICENSE and LICENSE-MIT files, so confirm the terms there before reuse.
Similar security for Hermes Agent
All securityShodan host intel, search, DNS and CVE lookups for Hermes Agent, with credit budgeting
skalenetwork ReefRun Hermes, OpenClaw and your own agents in microsandbox microVMs with TOML-defined policy
anpicasso Hermes Jev ApprovalsPlugin that serves TypeSafe's Jev model as the reviewer for Hermes Agent smart command approvals
Deconstruct2021 hermes-bumblebee-bridgeDaily read-only supply-chain scans for a Hermes Agent host using Perplexity's Bumblebee
nativ3ai Hermes PayGuardSafe-by-design USDC and x402 payment plugin for Hermes Agent with human approval for larger transfers
pawel-cell Agent Shopping Safe CheckoutSafe-checkout pattern for agents that buy online: isolated Chrome, virtual card and a human approval gate
Related guides: How to run Hermes Agent securely