# Bitdefender AI Guardian

> A macOS security layer that checks AI agent actions, tool calls, skills and file access against a policy and returns allowed, flagged or blocked verdicts.

Bitdefender AI Guardian is a security product from Bitdefender for autonomous AI agents on macOS. It inspects what an agent does, including tool calls, file access, prompts and skills, and returns a verdict of allowed, flagged or blocked against a policy baseline. It is currently in open BETA.

## What It Is

AI Guardian is an AI agent security layer that runs as a background service on the endpoint. It targets prompt injection, MCP tool poisoning, credential leakage and unauthorised actions. The product page states it is not a traditional antivirus, a network firewall or VPN, a replacement for an agent framework or LLM, or a content filter for chatbot text.

## How the policy, guardrail, verdict model works

The workflow has three stages. First, you set a policy baseline defining what agents may do with tools, files and actions. Second, every tool call and action is checked against that policy in real time and gets a verdict. Third, security events feed monitoring and response workflows, with an auditable record of what agents did.

## Protections

- MCP tool protection: detects and blocks malicious MCP tools before an agent calls them.
- Skill vetting: scans and validates agent skills before they run.
- Prompt injection detection: catches hijack attempts through crafted inputs and hidden instructions.
- Tool-call monitoring: watches each tool invocation in real time.
- Credential leak detection: detects exposure of secrets such as API keys before they leave the machine.
- Sensitive file protection: blocks unauthorised access to files such as SSH keys.

## Compatibility and setup

In BETA, supported CLI coding agents are Claude Code 2.1.121+ and OpenClaw 2026.6.6+, integrated through a plugin or hook. MCP clients and servers and agent skills and plugins are also covered, while IDE-embedded agents are listed as coming soon and Windows and Linux as planned. It installs from a signed macOS .dmg installer. Prompt data is analysed on-device, with some checks such as URL reputation using Bitdefender cloud services. Bitdefender notes that no security product guarantees complete protection.

## Features
- Policy baseline for agent permissions and auditing
- Allowed, flagged or blocked verdicts in real time
- MCP tool poisoning protection
- Agent skill vetting before execution
- Prompt injection detection
- Tool-call monitoring with auditable record
- Credential leak detection
- Sensitive file protection
- On-device prompt analysis

## Integrations
Claude Code, OpenClaw, Model Context Protocol (MCP)

## Platforms
WINDOWS, MACOS, LINUX, API, CLI

## Pricing
Free

## Links
- Website: https://ai.bitdefender.com/ai-guardian
- Documentation: https://ai.bitdefender.com/docs/ai-guardian
- EveryDev.ai: https://www.everydev.ai/tools/bitdefender-ai-guardian
