Download Latest Version agentguard_1.3.0_windows_amd64.zip (12.9 MB) Google Add to Preferred Sources
Home / v1.2.0
Name Modified Size InfoDownloads / Week
Parent folder
checksums.txt 2026-09-25 767 Bytes
install.ps1 2026-09-25 7.4 kB
agentguard_1.2.0_windows_arm64.zip 2026-09-25 11.3 MB
install.sh 2026-09-25 5.7 kB
agentguard_1.2.0_darwin_amd64.tar.gz 2026-09-25 12.5 MB
agentguard_1.2.0_darwin_arm64.tar.gz 2026-09-25 11.6 MB
agentguard_1.2.0_linux_amd64.tar.gz 2026-09-25 12.4 MB
agentguard_1.2.0_linux_arm64.tar.gz 2026-09-25 11.2 MB
agentguard_1.2.0_windows_amd64.zip 2026-09-25 12.6 MB
agentguard-v1.2.0.cdx.json 2026-09-24 18.5 kB
agentguard-v1.2.0.spdx.json 2026-09-24 28.4 kB
AgentGuard v1.2.0 source code.tar.gz 2026-09-24 1.2 MB
AgentGuard v1.2.0 source code.zip 2026-09-24 1.5 MB
README.md 2026-09-24 7.9 kB
Totals: 14 Items   74.4 MB 0

AgentGuard 1.2.0 — Release Notes

Released: 2026-09-24 Headline: A security release. Shell allow rules no longer let chained commands through, a second rule block for a scope is no longer ignored, and secrets are masked in the audit trail by default.

If your policy allows shell commands with patterns like ls * or git *, 1.1.x allowed agents to chain any command after them (ls /tmp; rm -rf /), past your deny and approval rules. Upgrade, then check your policy with agentguard validate --strict and the replay recipe in MIGRATION.md (github.com).


Why this release exists

1.1.1 was tested end to end on a local machine, not only in CI. The test ran every surface in a sandbox: the CLI, the server, approvals, audit, persistence, multi-tenant and multi-node PostgreSQL deployments, the MCP gateway, the LLM proxy, both SDKs and the dashboard. It sent spam, floods, malformed input and bypass attempts. It found:

  1. A policy bypass. A shell rule's glob matched the whole command line, and one * matched every shell operator in it. With the shipped default policy, ls /tmp; rm -rf /, git clone x && sudo rm -rf /, ls $(rm -rf ~) and echo x > /etc/passwd were all allowed, getting past its sudo and rm -rf approval rules.
  2. A second rule block for a scope was ignored whenever the first one decided, so a separate deny block could silently do nothing, and validate said the policy was valid.
  3. Secrets were stored verbatim in the audit trail and shown by the audit API, the live stream and the dashboard.
  4. pip install agentguardproxy[all] installed CrewAI 0.193, on which a crew ran its tools without a single policy check.
  5. Rerunning the test against the fixes found one more bypass: the MCP gateway checked a model-supplied domain argument instead of the host of the URL the tool would fetch.
  6. Six more medium-severity problems, among them: URL-only network checks ignored the URL; the lifetime decision counters lost the counts of pruned audit archives; agentguard audit showed the oldest entries instead of the newest; three MCP file-write tools passed the default policy; and the custom-tool snippet in two guides made the policy fail to load.

What changed

Shell commands are checked one command at a time

A command that contains shell syntax (;, &&, ||, |, &, a line break, $( ), backticks, a redirection) is split into the simple commands a shell would run, and each one must pass your rules; the most severe verdict wins. Redirection targets are checked against your filesystem rules. Whole-command deny and approval rules still run first, and a command with no shell syntax is matched exactly as before.

Command, with the default policy 1.1.x 1.2.0
ls /tmp; rm -rf / ALLOW REQUIRE_APPROVAL
ls /tmp && sudo rm -rf / ALLOW REQUIRE_APPROVAL
echo x > /etc/passwd ALLOW DENY
cat README.md \| head -5 ALLOW DENY: no rule allows head
git status && git diff ALLOW ALLOW

A pipeline is now allowed only when every command in it is, so add allow rules for the commands your agents chain. See Compound shell commands.

Policies load and match the way they read

  • Rule blocks for the same scope are merged at load, with a warning. Two such blocks with different rate or cost limits are a load error.
  • Likely-misspelled scope names warn (scope "shel" … did you mean "shell"?), and agentguard validate --strict fails on any warning.
  • url-only network and browser checks use the URL's host, as the policy reference always said. https://api.github.com@evil.com/ is checked as evil.com.
  • The MCP gateway checks the URL's host. A domain or host argument next to a url no longer stands in for it, so a model can't pair an allow-listed domain with a URL on another host. The Python MCP adapter is fixed the same way.

Secrets are masked in the audit trail

serve --audit-redact, on by default, masks keys, tokens, passwords, JWTs, private keys and credential headers before they reach the audit log, GET /v1/audit, the live stream, the dashboard and the pending-approvals list. It uses the same patterns as notifications, which gain sk-… API keys, Google keys, all GitHub token types, JWTs, PEM keys and Authorization headers, plus your policy's extra_patterns. The work happens in the audit workers, not on the /v1/check path. --audit-redact=false turns it off.

Audit and operations

  • agentguard audit shows the newest entries first (--order asc for the old order), and so does the dashboard's history. GET /v1/audit gains order=asc|desc; its default is unchanged.
  • Decision counters survive archive pruning: the replay checkpoint is rewritten on every rotation and at shutdown.
  • serve --bind <host> keeps a keyed server on one address, such as 127.0.0.1 behind a reverse proxy on the same host. A non-loopback --bind without --api-key refuses to start.
  • agentguard --version works like the other two binaries.

Default policy

find … -exec, -ok and -delete require approval. The filesystem MCP server's edit_file, move_file and create_directory tools are denied like write_file.

Python SDK

  • The CrewAI adapter requires CrewAI 1.0+ and refuses older versions, on which it couldn't gate crew tool calls. [all] now resolves to CrewAI 1.15, browser-use 0.11, LangChain 1.4 and MCP 1.28 with a clean pip check.
  • The mcp extra allows MCP 2.x.
  • agentguard.__version__ is new.

CI

The test_at_* suites (a real agent loop, the real LLM proxy, the MCP gateway against a real server) run in CI for the first time, and a new job installs [all] fresh and runs the whole Python suite.


Breaking changes

None in the public API. No field, route, flag, subcommand or schema version was removed or changed; everything new is additive.

The security fixes change behaviour:

  • Shell chains, pipelines and redirections are checked command by command, so some that 1.1.x allowed are now denied or sent to approval.
  • A second block for a scope now applies. Two blocks with different rate or cost limits make the policy fail to load.
  • url-only network and browser checks can be allowed where 1.1.x denied them, and MCP gateway calls with both a url and a domain argument are checked against the URL's host.
  • Audit content is masked by default, and agentguard audit lists newest first.
  • The CrewAI adapter needs CrewAI 1.0+.

Upgrade notes

  1. Run agentguard validate --strict --policy <your policy> with the 1.2.0 binary.
  2. Replay recent shell ALLOWs from your audit log through agentguard check --batch to see which chains 1.2.0 would stop, and add allow rules for the ones you want.
  3. Swap the binaries and SDKs. Nothing on disk changes format, and rolling back to 1.1.x is safe, but it brings back the bypasses.

Details: MIGRATION.md § v1.1.x → v1.2.0 (github.com).


Get started

:::bash
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard@v1.2.0
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-mcp-gateway@v1.2.0
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-llm-proxy@v1.2.0

pip install --upgrade "agentguardproxy==1.2.0"
npm install @lictorate/agentguard@1.2.0

# Docker: no image is published; build one from the repository's Dockerfile
docker build -t agentguard:1.2.0 .

Full change list: CHANGELOG.md § 1.2.0 (github.com).

Source: README.md, updated 2026-09-24