Skip to main content
Agent Guard protects the agent surface — AI that acts on its own through plans, memory, and multi-step execution. It follows an agent’s entire reasoning chain, not just its final action, holding the agent inside its mandate at every step.

What Agent Guard protects

Autonomous agents: the planning, memory, and execution loop that lets an agent pursue a goal across many steps and tool calls. A single hijacked instruction partway through a plan can push an agent to act well outside its intended scope, so enforcement has to watch the whole chain rather than a single request.

Threats it stops

  • Plan deviation — the agent’s execution trace is compared step by step against its authored plan; drift and out-of-scope actions are blocked (BG-10).
  • Memory poisoning — stored memory is treated as untrusted data, with write-time provenance checks and read-time conflict checks against policy (BG-12).
  • Infinite loops — repetitive or non-converging execution is detected and terminated through per-step timeout thresholds (BG-11).

How it works

Agent Guard evaluates the authored plan (a graph or state machine with pre- and post-conditions) against what the agent actually does, step by step. When execution diverges from the plan, calls an unwhitelisted tool, or stops converging, the action is blocked and the event is logged with a reason code. Deny-by-default is the operating principle across the chain.

Controls

Agent Guard runs BG-10, BG-11, and BG-12. See the Controls Catalog for each control’s definition, scope, and benchmark.

OWASP coverage

Addresses LLM06 Excessive Agency from the OWASP LLM Top 10, alongside MCP Guard.

MCP Guard

Validates the individual tool and function calls an agent makes.

Controls Catalog

The controls Agent Guard runs, in full detail.

Threat Model

How agentic threats fit the broader model.

Policy Configuration

Define plans, whitelists, and loop limits.