OPEN SOURCE · APACHE 2.0

AI agents are overprivileged
by default.

AgentWard enforces what they're allowed to touch — in code, not prompts. Scan, enforce, and audit every tool call.

View on GitHub
26%
of 31K skills have vulns
230+
malicious skills on ClawHub
140K+
OpenClaw stars, 0 governance
The Problem

Every tool scans. Nothing enforces.

Cisco, Snyk, and Caterpillar all scan before installation — then walk away. OpenClaw has 140K stars and gives agents full computer control with zero runtime governance. Prompt-based guardrails can be bypassed by prompt injection. You need enforcement in code, outside the LLM context window entirely.

Existing tools

Static scanners that check at install time, then stop watching. No runtime enforcement. No audit trail. No skill chaining controls. Lateral data movement between tools goes undetected. You're left hoping your prompts hold.

AgentWard

"Telling an agent 'don't touch the stove' is a natural-language guardrail that can be circumvented. AgentWard puts a physical lock on the stove — code-level enforcement that prompt injection can't override."

Live Demo

See it in action.

AgentWard scans every tool your agent can reach, risk-rates them, detects dangerous skill chains (lateral data movement between tools), generates a policy, and wires enforcement — all in seconds.

agentward scan · agentward init
What You'd See Running It

Full scan output, step by step.

agentward scan ~/
$
What It Does

Four stages. One command to run them all.

Run agentward init — or go step by step.

1
agentward scan

Scan

Map every tool your agent can reach. Risk ratings, data access patterns, dangerous skill chains — lateral movement paths that existing DLP and IAM don't cover.

2
agentward configure

Configure

Generate smart-default YAML policies from scan results — tailored to your use-case pattern.

3
agentward inspect

Enforce

Runtime proxy intercepts every tool call. Block, redact, or require human approval — in real time.

4
agentward comply

Comply

Evaluate policies against HIPAA, SOX, GDPR, PCI-DSS. Auto-generate compliant policy YAML with fixes applied.

Architecture & how it works → Full CLI reference → Compare vs. Cisco, Snyk →
Compatibility

Works with the tools you already use.

Claude Desktop Claude Code Cursor Windsurf VS Code OpenClaw / ClawdBot OpenAI SDKSOON LangChainSOON CrewAISOON

Python 3.11+ · No API key required · Everything runs locally · Mac + Linux

Stop YOLOing your agent permissions.

Start verifying.

5 seconds to see what your AI agent's tools can actually do.

GitHub Repo
Apache 2.0 · Python 3.11+ · No API key · Runs locally · [email protected]