Panguard AI provides the first Skills Audit for AI agents. It audits every skill before it runs, catches known threats with community ATR (Agent Threat Rules), catches unknown threats with AI analysis, and shares new rules to protect everyone. MIT licensed. Open source.
Trusted by security teams
See it in action
One command. Full protection.
Install PanGuard, and your AI agents are protected in under 60 seconds.

Real-time dashboard showing 188 active rules, event monitoring, and 3-layer detection status.
This is not hypothetical.
Real CVEs. Real attacks. Real victims.
Default 0.0.0.0 binding, one HTTP request = RCE. All versions before v1.4.3.
CVE-2026-23744Hooks + MCP config exploited for arbitrary shell execution and API key theft.
CVE-2025-59536 + CVE-2026-21852SSRF steals managed identity tokens. Attacker gains Azure resource access.
CVE-2026-26118Clean for 15 versions. v1.0.16 added silent BCC forwarding 3K-15K emails/day.
ATR ClawHub scanWe scanned 53,577 MCP skills. 2.4% have CRITICAL or HIGH security risks.
Why PanGuard
< 1 Hour Response
New threat to detection: industry takes weeks. PanGuard takes 1 hour. Community reports + LLM auto-review, not committee approvals.
Trust Network
Not antivirus. A trust rating for every MCP skill. Like SSL certificates for the agent ecosystem.
Collective Defense
Every scan makes everyone safer. One machine discovers a threat. One hour later, every machine is immune.
How we compare
| PanGuard | Cisco DefenseClaw | OWASP | |
|---|---|---|---|
| Rule update speed | < 1 hour (community + LLM) | Weeks (committee) | Months |
| Setup | 1 command | Enterprise deployment | N/A (framework only) |
| Cost | Free + open source | Free but enterprise-focused | Free (checklist only) |
| Who it's for | Individual developers | Enterprise security teams | Security architects |
PanGuard
Cisco DefenseClaw
OWASP
Threat Crystallization
AI understands new threats. Crystallizes them into regex rules. Executes in 0ms. Protects everyone.
Scan
Pattern-match against 108 ATR rules
3msEvery skill is checked against the full ATR rule set. Known patterns are caught instantly with zero false negatives on matched signatures.
Detect + Block
CRITICAL threats blocked immediately
< 1sHigh-confidence matches trigger instant response: block, quarantine, or alert. No human intervention needed for known threats.
Crystallize
LLM generates a new regex rule
< 1 hourWhen the LLM discovers a new attack pattern, it crystallizes the understanding into a deterministic regex rule. From probabilistic AI to deterministic defense.
Protect Everyone
New rule distributed to all users
all usersThe crystallized rule flows through Threat Cloud to every PanGuard installation. One discovery protects the entire network.
npm install -g @panguard-ai/panguard && pga up60 seconds. 16 platforms. 108 rules. Free forever.
The Mission: Decentralized AI Agent Security
Every device that installs PanGuard becomes a sensor.
Every scan discovers new threats.
Every threat crystallizes into a rule that protects everyone.
The more people use it, the safer the entire ecosystem becomes.
MIT Licensed / Paper published (Zenodo DOI)