Skip to main content

What is Panguard AI?

Panguard AI is an open-source security platform purpose-built for the AI agent era. As AI agents (Claude Code, Cursor, QClaw, OpenClaw, Codex CLI, WorkBuddy, NemoClaw, ArkClaw, Windsurf, Cline, VS Code Copilot, Zed, Gemini CLI, Continue, Roo Code) gain root access to production systems, Panguard provides the first open standard for detecting and blocking agent-level threats. Three pillars. One mission: secure every AI agent.
  1. ATR (Agent Threat Rules) — The open standard for AI agent threat detection (768 rules, 10 categories, OWASP 10/10)
  2. Threat Cloud — Collective immunity network that gets stronger with every install (11 intel sources, hourly sync)
  3. Guard — The enforcement engine with Skill Auditor, threat blocking, and auto-response (768 ATR rules)

Three Pillars

ATR -- The Standard

768 rules across 10 threat categories. OWASP 10/10. The first open standard for AI agent threats — purpose-built for prompt injection, tool poisoning, skill compromise, and agent manipulation. YAML-based, human-readable, machine-enforceable.

Threat Cloud -- The Network

Collective immunity. Every Panguard install contributes anonymized threat signals. The pipeline auto-generates ATR rules from real-world attacks via Claude Sonnet 4 LLM review. 11 threat intel sources, 5,000+ validated IoC records, synced every hour.

Guard -- The Engine

768 ATR detection rules. A 4-agent AI pipeline (Detect, Analyze, Respond, Report) processes OS-level events through ATR rules. Built-in Skill Auditor gates every AI skill before install. Auto-response blocks IPs, kills processes, quarantines files.

Additional Tools

Panguard Scan

60-second security audit. One-time scan producing a risk score (0-100, grades A-F), PDF report, and compliance reports (ISO 27001, SOC 2, TCSA). Covers ports, services, firewall, SSL/TLS, password policy, and CVE lookup. MIT licensed.

MCP Server

AI assistant integration. 12 MCP tools let Claude Desktop, Cursor, and Claude Code control Panguard directly through natural language.

Skill Auditor

Pre-install security gate. 8-check analysis of AI skill manifests for prompt injection, tool poisoning, secrets, and unsafe dependencies before installation.

Three-Layer AI Architecture

Panguard uses a layered AI funnel that balances speed, cost, and accuracy. Each layer handles progressively fewer — but more complex — events.
Resilient by design. If Cloud AI is unavailable, Local AI takes over. If Local AI is down, the rules engine keeps running. Protection never stops.
For a deep dive into the AI architecture, see Three-Layer AI.

Technology Stack

Platform Support

Panguard integrates with 17 AI agent platforms via MCP or native Skill protocol: All platforms are auto-configured with a single panguard setup command.

100% Open Source

Panguard AI Community is released under the MIT License — full source, unlimited self-host, no signup required. Every line is auditable. For production deployments at F500 scale, Enterprise (150K500K/year),MigratorPro(150K-500K / year), Migrator Pro (500K-2M / year), and Sovereign ($5-20M / nation) tiers add signed, continuously re-scanned compliance evidence, airgap deployment, and SLA. See pricing.

View on GitHub

Browse the source code, report issues, or contribute to the project.

ATR Rules on GitHub

Contribute ATR rules — every new rule strengthens collective immunity for all users.