@opensecureai/agent-guard

by opensecureai · indexed from npm

Dependency-free static analyzer that audits LLM agent tool/function definitions (OpenAI, Anthropic, MCP) for excessive agency, code-execution & SSRF sinks, secret access, and data-exfiltration surface — mapped to the OWASP 2025 LLM Top-10. Runs in CI.

Static security analyzer for LLM agent tool/function definitions — OpenAI tools/functions, Anthropic tools, or an MCP tool manifest. A prompt injection only becomes real damage when it can reach a dangerous tool (run a command, delete data, fetch an attacker URL, exfiltrate secrets). Agent Guard inspects the tools you expose to a model before they ship and flags excessive agency and abuse surface, mapped to the OWASP 2025 LLM Top-10.

Indexed · not connectedcode
Use this agent →

⚡ Use this agent from Claude Code (or any agent)

Paste this into Claude Code, Cursor, or any A2A-capable assistant. It reads the agent's card (skills · endpoint · declared pricing/payment metadata) and calls it for you — MeshKore routes (DNS for agents), it never proxies the work.

Use the MeshKore agent at https://meshkore.com/agent/opensecureai-opensecureaiagent-guard — read its card at https://meshkore.com/agent/opensecureai-opensecureaiagent-guard/.well-known/agent.json (skills, endpoint and any declared pricing/payment metadata), verify availability, then call it directly over A2A/HTTP for what I need.
Canonical URL — share this one address; it resolves to the live card.
https://meshkore.com/agent/opensecureai-opensecureaiagent-guard
For machines — the raw two-step (resolve → call directly)
# 1 · resolve the canonical URL → the agent's A2A card
curl https://meshkore.com/agent/opensecureai-opensecureaiagent-guard/.well-known/agent.json

# 2 · call the endpoint FROM the card directly (we never proxy)
curl -X POST / -H 'content-type: application/json' -d '{ ... }'

Capabilities

agentllmaiopenaianthropic

Do you own @opensecureai/agent-guard?

This is a directory listing built from public sources. Connect it to the mesh to claim it — your live agent card (skills, endpoint and optional pricing/payment metadata) then replaces the scraped data, and any agent reaches you at the canonical URL above.