EveryDev.ai
Subscribe
Home
Tools

3,223+ AI tools

  • New
  • Trending
  • Featured
  • Compare
  • Arena
Categories
  • Agents2189
  • Coding1574
  • Infrastructure698
  • Marketing534
  • Projects498
  • Research456
  • Design416
  • Analytics389
  • Testing296
  • MCP290
  • Security286
  • Data262
  • Integration197
  • Prompts189
  • Communication183
  • Extensions173
  • Learning170
  • Voice151
  • Commerce135
  • DevOps123
  • Web86
  • Finance26
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Tools
    3. PanGuard AI
    PanGuard AI icon

    PanGuard AI

    Application Security

    Open-source AI agent security platform that audits skills before install, monitors agent behavior at runtime, and shares threat intelligence via the ATR open standard.

    Visit Website

    At a Glance

    Pricing
    Open Source
    Free tier available

    Full open-source stack for individual developers, small teams, and anyone who wants to self-host. MIT licensed, no usage limits, no signup required.

    Founding Pilot: $25000 one-time
    Enterprise: $150000/yr
    Sovereign: Custom/contact
    +1 more plan

    Engagement

    Available On

    Windows
    macOS
    Linux
    iOS
    Web

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Application SecurityAgent FrameworksThreat Detection

    Alternatives

    SkillSpectorIronClawSocket
    Developer
    Panguard AI, Inc.Taipei, TaiwanEst. 2026

    Listed Jul 2026

    About PanGuard AI

    PanGuard AI is a free, MIT-licensed security platform built specifically for the AI agent era. Developed solo by Adam Lin (林冠辛) in Taipei, Taiwan, it addresses a gap that traditional security tools miss: AI agents installing skills and MCP servers with full system access and zero review process. The current release is v1.8.26, installable in a single command with no account or signup required.

    What It Is

    PanGuard AI is an open-source firewall and skills auditor for AI agents. It operates across three pillars: ATR (Agent Threat Rules), an open, executable detection standard analogous to Sigma for SIEM or YARA for malware; Threat Cloud, a self-hosted collective intelligence network that auto-generates new ATR rules from real-world attacks; and Guard, a 4-agent enforcement pipeline (Detect, Analyze, Respond, Report) that processes OS-level events through 768 ATR detection rules. The core runtime, CLI, MCP server, and all 768 ATR rules are MIT-licensed and free forever.

    How the Detection Architecture Works

    PanGuard uses a three-layer detection model designed to be deterministic by default and AI-enhanced optionally:

    • Layer A — ATR rules engine: 768 regex/AST rules evaluated in under 50ms per event. Auto-blocks on match. Zero cost, works offline.
    • Layer B — On-device heuristics: Behavioral fingerprinting that detects drift from a skill's declared capabilities. Also auto-blocks.
    • Layer C — Optional LLM second opinion: Bring your own key (Anthropic, OpenAI) or run locally via Ollama. Flags for human review only — never auto-blocks.

    The Skill Auditor runs 8 checks before any AI skill is installed, gating supply-chain attacks before they reach the agent. At runtime, Guard monitors every whitelisted skill continuously and responds based on confidence thresholds: at ≥85% confidence, it auto-revokes the skill, blocks tool invocation, and quarantines the session.

    ATR Standard and Ecosystem Adoption

    ATR (Agent Threat Rules) is an independent, MIT-licensed open standard for AI agent threat detection, crosswalked to 10 frameworks including EU AI Act, NIST AI RMF, ISO/IEC 42001, OWASP Agentic Top 10, MITRE ATLAS, and CISA KEV. The vendor reports that ATR rules have been merged upstream into Cisco AI Defense (314 rules, PR #79 and #99) and Microsoft Agent Governance Toolkit (287 rules, PR #908 and #1277), as well as MISP and the OWASP Agentic Security Resource Hub — described by the project as maintainer-accepted contributions, not vendor endorsements.

    The platform currently supports 17 AI agent platforms, including Claude Code, Claude Desktop, Cursor, Codex CLI, Windsurf, Cline, VS Code Copilot, Zed, Gemini CLI, Continue, Roo Code, and several others. It auto-detects all installed platforms on setup.

    Benchmarks and Coverage

    The project publishes corpus-level benchmark results on its research page:

    • SKILL.md corpus (498 real-world samples): 100% recall, 97% precision, 0.2% false-positive rate
    • Garak benchmark (650 samples, ATR-core families): ~97–98% recall
    • PINT prompt-injection corpus (850 samples): 63.2% recall, 99.7% precision
    • HackAPrompt: 69.6% recall vs. 28.6% baseline, 100% precision
    • OWASP Agentic Top 10 2026: full 10/10 coverage across 768 rules

    The vendor notes that false-positive rates are lane-based: approximately 0.24% in enforce mode and ~9% in hunt mode (the default), and cautions against quoting a single blended number.

    Update: v1.8.26

    The latest release, v1.8.26 (published 2026-07-19), ships support for 17 AI platforms, 768 ATR rules, full OWASP Agentic Top 10 coverage, and reports 67,799 skills scanned with 1,096 confirmed malicious. The project is written in TypeScript (strict), targets Node.js 20+, and uses a pnpm monorepo with packages for the CLI, guard daemon, MCP proxy, skill auditor, MCP server, migrator, and website. The GitHub repository was created in February 2026 and has been actively pushed as recently as July 2026.

    Deployment Model and Privacy

    PanGuard runs entirely on-device by default. No telemetry leaves the machine unless the user explicitly opts into Threat Cloud participation. When Threat Cloud is enabled, only anonymized threat signatures are shared — matched rule ID, attack category, MITRE technique, coarse country region, and a truncated IP. Prompts, code, file contents, secrets, and hostnames are never transmitted. Inbound community rules are ed25519 signature-verified and fail-closed. The platform supports Linux, macOS, Windows, Docker, and Kubernetes deployments, and is designed for airgap operation.

    PanGuard AI - 1

    Community Discussions

    Be the first to start a conversation about PanGuard AI

    Share your experience with PanGuard AI, ask questions, or help others learn from your insights.

    Pricing

    FREE

    Community

    Full open-source stack for individual developers, small teams, and anyone who wants to self-host. MIT licensed, no usage limits, no signup required.

    • 768 ATR detection rules (MIT licensed)
    • Unlimited agents / endpoints / tenants
    • 5 layers shipped: Audit · Protect · Detect · Deceive · Respond
    • Threat Cloud rule updates (< 24h)
    • Community support on GitHub + Discord

    Founding Pilot

    For AI vendors and regulated teams that must prove agent security inside an enterprise or bank security review. 90-day founder-led delivery.

    $25000
    one time
    • 90-day founder-led delivery
    • Day-3 initial scan + findings report (within refund window)
    • ATR engine deployment + custom 50-100 rule pack
    • SIEM webhook integration
    • Signed compliance evidence pack (EU AI Act / NIST AI RMF / ISO 42001 / OWASP)
    • 7-day no-questions refund
    • $25K credits to Y1 Enterprise

    Enterprise

    Regulated enterprises needing living compliance evidence, on-prem/airgap deployment, SSO, SIEM, and dedicated support. Sales-led.

    $150000/yr
    billed annually
    • Scan + Guard + support
    • On-prem / airgap / SSO / SIEM
    • Migrator Pro: living signed compliance evidence, migrates 15 legacy formats
    • Truly unlimited agents, tenants, seats, and sites
    • SAML SSO, SCIM, SIEM webhook, audit log export
    • Dedicated Customer Success Manager
    • Priority rule update SLA within 4 hours

    Sovereign

    Nation-scale airgap deployment for sovereign AI programs. Full ATR, Migrator Pro, Compliance Module, Threat Cloud, in-region deployment, and custom rule packs.

    Custom
    contact sales
    • Nation-scale airgap deployment
    • Full ATR, Migrator Pro, Compliance Module, Threat Cloud
    • In-region deployment
    • Custom rule packs
    • Delivery via certified regional enterprise vendor partner

    ATR Enterprise Member

    Annual membership in the ATR standards organization. Logo on ATR registry, governance vote, priority PR review, early draft rule access, and roadmap seat.

    $833/mo
    billed annually
    • Logo on ATR registry
    • Governance vote
    • Priority PR review
    • Early draft rule access
    • Seat in annual roadmap meeting
    View official pricing

    Capabilities

    Key Features

    • 768 ATR detection rules (MIT licensed)
    • Skill Auditor with 8-layer pre-install security gate
    • 4-agent AI pipeline: Detect, Analyze, Respond, Report
    • Runtime guard monitoring every agent tool call
    • 3 auto-response modules: IP Blocker, Process Killer, File Quarantine
    • Threat Cloud collective intelligence network
    • Local dashboard at http://127.0.0.1:9100
    • SARIF 2.1.0 output for CI integration
    • MCP server with 12 security tools
    • Auto-detects 17 AI platforms on setup
    • Three-layer detection: rules engine, local AI (Ollama), cloud AI
    • OWASP Agentic Top 10 full coverage
    • Crosswalked to EU AI Act, NIST AI RMF, ISO/IEC 42001, MITRE ATLAS
    • Zero telemetry by default, fully offline capable
    • Community flywheel: new threats auto-generate ATR rules for all users
    • Signed compliance evidence reporting (Enterprise)
    • SIEM webhook integration (Enterprise)
    • Honeypot Trap included in Community edition
    • Sub-millisecond ATR rule evaluation
    • Behavioral fingerprint drift detection

    Integrations

    Claude Code
    Claude Desktop
    Cursor
    Codex CLI
    Windsurf
    Cline
    VS Code Copilot
    Zed
    Gemini CLI
    Continue
    Roo Code
    OpenClaw
    NemoClaw
    ArkClaw
    QClaw
    WorkBuddy
    Hermes Agent
    Ollama
    Anthropic API
    OpenAI API
    Cisco AI Defense
    Microsoft Agent Governance Toolkit
    MISP
    OWASP
    Slack
    Telegram
    Email
    LINE
    Docker
    Kubernetes
    API Available
    View Docs

    Ratings & Reviews

    No ratings yet

    Be the first to rate PanGuard AI and help others make informed decisions.

    Developer

    Panguard AI, Inc.

    Panguard AI builds open-source security infrastructure for the AI agent era, headquartered in Taipei, Taiwan. The company's flagship product, PanGuard, audits AI agent skills before install, monitors agent behavior at runtime, and shares threat intelligence through the ATR open standard. Founded by Adam Lin (林冠辛), a self-taught developer with backgrounds in sales, marketing, and festival production, the team operates on the thesis that AI agent security should be a public good — free, open, and community-owned. ATR rules developed by Panguard have been merged upstream into Cisco AI Defense and Microsoft's Agent Governance Toolkit as maintainer-accepted contributions.

    Founded 2026
    Taipei, Taiwan
    3 employees
    Read more about Panguard AI, Inc.
    WebsiteGitHubLinkedIn
    1 tool in directory

    Similar Tools

    SkillSpector icon

    SkillSpector

    Open-source security scanner for AI agent skills that detects vulnerabilities, malicious patterns, and security risks before installation using static analysis and optional LLM evaluation.

    IronClaw icon

    IronClaw

    IronClaw is a secure, open-source AI agent platform built in Rust that runs in encrypted enclaves on NEAR AI Cloud, keeping your credentials safe from LLM exposure.

    Socket icon

    Socket

    Socket blocks malicious open source packages before they reach your code by proactively analyzing dependency behavior across all major registries.

    Browse all tools

    Related Topics

    Application Security

    AI tools for securing software applications and identifying vulnerabilities.

    102 tools

    Agent Frameworks

    Tools and platforms for building and deploying custom AI agents.

    517 tools

    Threat Detection

    AI tools that detect and analyze security threats and anomalies.

    32 tools
    Browse all topics
    Back to all toolsSuggest an edit
    ratings
    discussions