Documentation

AgentX is a runtime firewall for AI agents. It blocks catastrophic tool calls (DROP TABLE, secret exfiltration, SSRF) before they execute, then coaches the agent to a safe path so the run finishes. Pick your path below and start keyless in 30 seconds.

01Get started

Pick your language. Each path shows only its own steps, numbered in the order you take them.

This path is for a TypeScript tool your code calls directly, a Vercel AI SDK tool() or any object with an execute function, not behind an MCP server. If your agent reaches its tools through MCP servers instead, the keyless agentx-mcp proxy protects those today with no code change and no key: switch to the MCP tab above.

TypeScriptFree · no key

Wrap a tool in one line. Every call it makes is written down on your machine (tool and argument names, no values), and audit prints what your agent did. Nothing is blocked, so your agent runs as it does today.

npm install @agentx-core/security-sdk
import { agentxWatchAll }
  from "@agentx-core/security-sdk";

// was: tools: { runSql, sendEmail }
tools: agentxWatchAll({ runSql, sendEmail })

Your tools behave exactly as they do today: the wrap watches and records, and blocks nothing. See what it recorded with npx @agentx-core/security-sdk audit

Inventory first? Lists every tool your agent can call, ranked by risk, with no install:

npx @agentx-core/scan .

Step up to the gateway below to block: the in-process guard, set up with you.

02Wrap a tool, then see what it recorded

One line around each tool. Your tools run exactly as before; every call is written down in the folder your agent runs from.

import { agentxWatchAll } from "@agentx-core/security-sdk";

const result = await generateText({
  model,
  tools: agentxWatchAll({ runSql, sendEmail }),   // was: tools: { runSql, sendEmail }
  prompt,
});

Then, from that folder, see which tools your agent called, how many times, what each one touched, which wrapped tools it never reached for, and what is new since you last looked:

npx @agentx-core/security-sdk audit   # grouped by tool
4 calls across 3 tools since 2026-09-14 15:09
4 tools wrapped. 3 called. 1 never ran.

TOOL                   CALLS  SURFACE       ARGUMENTS
-----------------------------------------------------------------------
runSql                     2  DB            limit, sql
refund                     1  -             amount, currency, order_id
                              largest amount passed: ≥100,000
sendEmail                  1  -             body, to

NEW SINCE YOU LAST LOOKED
  sendEmail                first time we have seen this tool

The last block is one line per change since the previous read, and absent when nothing changed. A repeat run that does exactly what the last one did prints nothing there.

npx @agentx-core/security-sdk audit --calls   # one row per call, newest first

--json prints the same data for a program, always complete, with the exit code carrying the CI verdict below.

The file holds tool and argument names, no values. Only wrapped tools appear. Nothing is blocked.

In CI, fail the job when there was nothing to read, so a run where the agent never ran cannot pass as a clean audit:

npx @agentx-core/security-sdk@^0.2.0 audit --require-calls   # exits 2 on an empty record

The whole GitHub Actions job, with the record kept as a build artifact, is in the package README on npm.

To watch a dangerous call get stopped and coached (step 05 adds this to your tools):

Open the playground

03Watch → Recover → Control

WatchFree · Local

npm install, then one line around your tools: agentxWatchAll({ ... }). Every call is written down on your machine (tool and argument names, no values), and `npx @agentx-core/security-sdk audit` prints what your agent did. Nothing is blocked. No key, no signup.

record + report

RecoverGateway + Gemini key

The gateway adds the full deterministic floor (AST parsing, the SSRF normalizer, the whole failure catalog) and tracks session state: budget ceilings and no-progress loop breaking that a single stateless call can't see. Its judge catches what keyword rules can't, writes the safe path when your policy carries none, and runs the coach-and-retry for you, so your agent finishes the task instead of dying on a 403. Needs the gateway and your own Gemini key. An install with an AGENTX_API_KEY set enforces by default: what Watch wrote down, Recover stops. Set AGENTX_POSTURE=audit any time you want it watching instead.

guide + continue

Get the gateway
Control+ Team

Connect the cloud control plane for team human-in-the-loop and SOC approvals, shared dashboards, and a fleet-wide audit trail. Central oversight for when one machine isn't the whole story.

review + govern

Request Access

Recover and Control run through the gateway. Watch records what your agent did and blocks nothing; enforcement starts at Recover, where the full deterministic floor and session state (budget ceilings, no-progress loop breaking) check each call, backed by a judge that catches what keyword rules miss.

04Run the gateway

The gateway adds the full deterministic floor (AST parsing, the SSRF normalizer, the whole failure catalog), coached recovery, and team review and approval before a risky action runs.

docker compose up -d   # the full floor + Recover run here

Stand it up now. Traffic starts flowing through it once we wire your guard, which is the next step.

It is free and runs locally: get it self-serve. Questions or something broke? Join the Discord.

The gatewayFree · self-serve

Where your guarded TypeScript tools send every call. The full deterministic floor (AST parsing, the SSRF normalizer, the whole failure catalog), coached recovery that finishes the run, and team review before a risky action runs.

The floor runs with no key at all. Your own Gemini key turns on Recover, which writes the safe path and runs the retry for you.

05Turn it on in your code

To stop a call, an in-process guard wraps each tool and checks it against the gateway before it runs. A blocked action never executes, and your agent gets the same coaching to recover that the Python decorator delivers. The guard needs a gateway key, so we set it up with you: say hello in our Discord.