What Agent Guard protects
Autonomous agents: the planning, memory, and execution loop that lets an agent pursue a goal across many steps and tool calls. A single hijacked instruction partway through a plan can push an agent to act well outside its intended scope, so enforcement has to watch the whole chain rather than a single request.Threats it stops
- Plan deviation — the agent’s execution trace is compared step by step against its authored plan; drift and out-of-scope actions are blocked (
BG-10). - Memory poisoning — stored memory is treated as untrusted data, with write-time provenance checks and read-time conflict checks against policy (
BG-12). - Infinite loops — repetitive or non-converging execution is detected and terminated through per-step timeout thresholds (
BG-11).
How it works
Agent Guard evaluates the authored plan (a graph or state machine with pre- and post-conditions) against what the agent actually does, step by step. When execution diverges from the plan, calls an unwhitelisted tool, or stops converging, the action is blocked and the event is logged with a reason code. Deny-by-default is the operating principle across the chain.Controls
Agent Guard runsBG-10, BG-11, and BG-12. See the Controls Catalog for each control’s definition, scope, and benchmark.
OWASP coverage
Addresses LLM06 Excessive Agency from the OWASP LLM Top 10, alongside MCP Guard.Related
MCP Guard
Validates the individual tool and function calls an agent makes.
Controls Catalog
The controls Agent Guard runs, in full detail.
Threat Model
How agentic threats fit the broader model.
Policy Configuration
Define plans, whitelists, and loop limits.