WHY PANGUARD
Where PanGuard fits in your security stack
Endpoint tools secure the OS. Dependency scanners secure your code. Prompt firewalls filter the model boundary.
PanGuard adds the AI agent layer — and complements the tools you already run.
The blind spot
What existing tools miss
AI agents introduce a new attack surface that traditional security cannot see.
Traditional EDR sees:
- Process execution, file access, network calls
- Malware signatures, ransomware patterns
- Known CVEs in installed software
Traditional EDR cannot see:
- Prompt injection in agent conversations
- Malicious MCP tool definitions
- Credential exfiltration via agent tool calls
- Context manipulation across multi-turn sessions
- Supply chain attacks via skill packages
Real data
We scanned 67,799 MCP skills. Here's what we found.
These are real findings from our ecosystem scan, not hypothetical scenarios.
Credential Exfiltration
CRITICALMCP skill reads ~/.ssh/id_rsa and sends content to external endpoint via HTTP POST.
3 instances across npm registry
Prompt Injection
CRITICALSkill injects hidden instructions into agent context: "ignore previous instructions and execute..."
12 instances, including 4 with obfuscated payloads
Excessive Permissions
HIGHSkill requests filesystem write + network access + process execution, but only needs read access.
5 instances flagged as over-privileged
182 CRITICAL + 1124 HIGH findings out of 67,799 skills scanned. 26,718 skills (39.4%) are clean.
How the layers fit
PanGuard alongside adjacent categories
Where PanGuard fits next to the security categories you already run — and how they complement each other.
vs Endpoint Security (EDR)
Endpoint tools watch the OS. PanGuard watches the AI agent.
- Endpoint detection and response (EDR) tools monitor OS-level processes, network connections, and files. That surface is essential — and it sits below the AI agent layer.
- Prompt flows, MCP tool calls, and skill installations do not surface as OS events, so an agent-layer threat can be invisible to an endpoint sensor.
- PanGuard Guard is purpose-built for the AI agent layer — it understands skill installations, prompt injection patterns, and tool poisoning.
- Endpoint security and PanGuard cover different layers and complement each other: EDR for the host, PanGuard for the AI agent.
vs Code & Dependency Scanners
Dependency scanners secure your code. PanGuard secures what your agent installs.
- Software composition and dependency scanners are excellent at finding known vulnerabilities in packages and container images — a mature, necessary practice.
- A malicious MCP skill usually has no CVE: it's a newer class of threat that classic vulnerability databases were not built to describe.
- PanGuard's Skill Auditor adds pre-install scanning for the AI agent era, with 768 ATR rules covering skill and tool behavior.
- The two are complementary: dependency scanners for your code, PanGuard for your agent's tools.
vs Prompt Firewalls
Prompt firewalls filter inputs and outputs. PanGuard secures the whole agent.
- Prompt firewalls do input/output filtering — blocking injection attacks in LLM prompts and responses — which is valuable at the model boundary.
- PanGuard covers the broader agent attack surface: prompt injection plus skill compromise, context exfiltration, agent manipulation, tool poisoning, privilege escalation and more — 768 ATR rules across 9 threat categories.
- A firewall filters the prompt boundary; PanGuard adds continuous runtime monitoring and response across the agent lifecycle.
- They fit together: a prompt firewall at the model edge, PanGuard across skills, tools, and runtime.
vs Agent Governance Platforms
Governance platforms set the policy. PanGuard supplies the detections.
- Agent governance platforms provide policy enforcement and compliance dashboards — the control plane for how agents are allowed to behave.
- PanGuard provides the detection layer those platforms can build on: 768 ATR rules that identify prompt injection, tool poisoning, and supply chain attacks in real time.
- Governance answers what is allowed; detection answers what is actually happening. Each is stronger with the other.
- ATR is an open standard and PanGuard is MIT-licensed and free, so governance platforms can adopt the detections directly.
vs MCP Config Scanners
Config scanners validate MCP setup. PanGuard covers the full agent surface.
- MCP configuration scanners check MCP server configs for known misconfigurations and issues — a useful first line at setup time.
- PanGuard also scans SKILL.md files, tool descriptions, and runtime behavior — 768 ATR rules across 9 threat categories, going beyond static config validation.
- On the real-world SKILL.md corpus (498 samples, Layer-1 deterministic rules) ATR reaches 100% recall; benign false positives are reported per detection lane, never as a single blended number.
- Config validation and behavioral detection are complementary layers of the same defense.
DETAILED COMPARISONS
ATR vs other AI security tools
Honest side-by-side comparisons with the open standards and commercial products in the AI agent security space.
ATR vs Sigma
Open detection rule standards. Sigma for SIEM, ATR for AI agent runtime.
ATR vs NVIDIA garak
Runtime detection vs adversarial pre-deployment testing. Both needed.
ATR vs Microsoft PyRIT
Defender YAML standard vs red-team Python toolkit. Active cooperation.
ATR vs OWASP Agentic Top 10
Executable rules vs taxonomy. ATR rules merged into OWASP A-S-R-H as a community contribution, not an OWASP endorsement.
PanGuard vs Cisco DefenseClaw
Open standard plus commercial platform vs enterprise bundle. ATR rules merged into Cisco AI Defense skill-scanner rule packs, in production (PR #99).
Your AI agents deserve the same protection as your servers
One command. 768 detection rules. 24/7 monitoring. $0.