The runtime firewall that keeps AI agents alive.
Block the catastrophic deterministically.Coach the recoverable.
A prompt-injected DROP TABLE runs anyway. Watching blocks nothing, and the calls it has never seen before get flagged.
No key to start, your data does not leave your machine, and a block hands your agent a safe path to finish, not die on a 403.
Wrap a tool in one line. Every call it makes is written down on your machine (tool and argument names, no values), and audit prints what your agent did. Nothing is blocked, so your agent runs as it does today.
npm install @agentx-core/security-sdkimport { agentxWatchAll }
from "@agentx-core/security-sdk";
// was: tools: { runSql, sendEmail }
tools: agentxWatchAll({ runSql, sendEmail })Your tools behave exactly as they do today: the wrap watches and records, and blocks nothing. See what it recorded with npx @agentx-core/security-sdk audit
Inventory first? Lists every tool your agent can call, ranked by risk, with no install:
npx @agentx-core/scan .Step up to the gateway below to block: the in-process guard, set up with you.
One decorator, @agentx_protect, on any tool catches the dangerous call in process RAM before it runs, no key.
pip install agentx-security-sdkfrom agentx_sdk import agentx_protect
@agentx_protect(agent_id="crm")
def call_api(url):
return requests.get(url)
# the agent picks the url at runtime:
call_api("http://169.254.169.254/")The tool behaves exactly as it does today: the wrap watches and records, and blocks nothing. Add posture="enforce" to the decorator above when you want it stopping calls, and it keeps blocking until you delete the argument. See what it recorded with agentx audit
Step up to the gateway below for the full floor and Recover.
One line in mcp.json wraps any server. The dangerous tools/call never reaches it, and the agent is coached to self-correct keyless.
{
"mcpServers": {
"filesystem": {
"command": "uvx",
"args": [
"agentx-mcp", "npx", "-y",
"@modelcontextprotocol/server-filesystem",
"/data"
]
}
}
}Config uses uvx (no install). Want to watch it block something first?
Trying it on servers you already use? A wrapped server records every call and blocks none of them. AGENTX_POSTURE=enforce in that server's env is how you make it start blocking. Add it per server block; the ones you leave alone keep watching. Read it back with uvx agentx-mcp --audit.
This is keyless and it is your protection for MCP servers today. Gateway-backed Recover over MCP is on the roadmap.
Want the gateway to cover your MCP traffic too?
Where the Python and TypeScript paths step up. The full deterministic floor (AST parsing, the SSRF normalizer, the whole failure catalog), coached recovery that finishes the run, and team review before a risky action runs.
The Python decorator and the agentx-mcp proxy run the keyless Shield first, and the TypeScript SDK watches and records, all with no key and nothing but counts leaving your machine. The gateway adds the full deterministic floor for Python and TypeScript tools, still with no key; your own Gemini key turns on Recover. Over MCP it is on the roadmap.
Full quickstart for your language → one numbered path, start to finish.
pip install and one decorator on a Python tool, one line in your mcp.json to wrap any MCP server, or npm install @agentx-core/security-sdk and one line around a TypeScript tool. Python and MCP screen every call against the keyless floor (DROP TABLE, secret exfiltration, SSRF) and write down what they find; TypeScript writes down every call. Out of the box nothing is blocked. Set AGENTX_POSTURE=enforce (Python and MCP) and the same floor stops those calls and coaches your agent to self-correct. No LLM key, no signup, runs on your machine.
record + report
The gateway adds the full deterministic floor (AST parsing, the SSRF normalizer, the whole failure catalog) and tracks session state: budget ceilings and no-progress loop breaking that a single stateless call can't see. Its judge catches what keyword rules can't, writes the safe path when your policy carries none, and runs the coach-and-retry for you, so your agent finishes the task instead of dying on a 403. Needs the gateway and your own Gemini key. An install with an AGENTX_API_KEY set enforces by default: what Watch wrote down, Recover stops. Set AGENTX_POSTURE=audit any time you want it watching instead.
guide + continue
Get the gatewayConnect the cloud control plane for team human-in-the-loop and SOC approvals, shared dashboards, and a fleet-wide audit trail. Central oversight for when one machine isn't the whole story.
review + govern
Request AccessNeed team control?
The gateway is free and self-serve: get it here, no wait. This list is for Control: the cloud control plane with team human-in-the-loop, SOC approvals, and shared dashboards.