| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| checksums.txt | 2026-09-25 | 767 Bytes | |
| install.ps1 | 2026-09-25 | 7.4 kB | |
| agentguard_1.2.0_windows_arm64.zip | 2026-09-25 | 11.3 MB | |
| install.sh | 2026-09-25 | 5.7 kB | |
| agentguard_1.2.0_darwin_amd64.tar.gz | 2026-09-25 | 12.5 MB | |
| agentguard_1.2.0_darwin_arm64.tar.gz | 2026-09-25 | 11.6 MB | |
| agentguard_1.2.0_linux_amd64.tar.gz | 2026-09-25 | 12.4 MB | |
| agentguard_1.2.0_linux_arm64.tar.gz | 2026-09-25 | 11.2 MB | |
| agentguard_1.2.0_windows_amd64.zip | 2026-09-25 | 12.6 MB | |
| agentguard-v1.2.0.cdx.json | 2026-09-24 | 18.5 kB | |
| agentguard-v1.2.0.spdx.json | 2026-09-24 | 28.4 kB | |
| AgentGuard v1.2.0 source code.tar.gz | 2026-09-24 | 1.2 MB | |
| AgentGuard v1.2.0 source code.zip | 2026-09-24 | 1.5 MB | |
| README.md | 2026-09-24 | 7.9 kB | |
| Totals: 14 Items | 74.4 MB | 0 | |
AgentGuard 1.2.0 — Release Notes
Released: 2026-09-24 Headline: A security release. Shell allow rules no longer let chained commands through, a second rule block for a scope is no longer ignored, and secrets are masked in the audit trail by default.
If your policy allows shell commands with patterns like
ls *orgit *, 1.1.x allowed agents to chain any command after them (ls /tmp; rm -rf /), past your deny and approval rules. Upgrade, then check your policy withagentguard validate --strictand the replay recipe inMIGRATION.md(github.com).
Why this release exists
1.1.1 was tested end to end on a local machine, not only in CI. The test ran every surface in a sandbox: the CLI, the server, approvals, audit, persistence, multi-tenant and multi-node PostgreSQL deployments, the MCP gateway, the LLM proxy, both SDKs and the dashboard. It sent spam, floods, malformed input and bypass attempts. It found:
- A policy bypass. A shell rule's glob matched the whole command line, and one
*matched every shell operator in it. With the shipped default policy,ls /tmp; rm -rf /,git clone x && sudo rm -rf /,ls $(rm -rf ~)andecho x > /etc/passwdwere all allowed, getting past itssudoandrm -rfapproval rules. - A second rule block for a scope was ignored whenever the first one decided, so a separate
denyblock could silently do nothing, andvalidatesaid the policy was valid. - Secrets were stored verbatim in the audit trail and shown by the audit API, the live stream and the dashboard.
pip install agentguardproxy[all]installed CrewAI 0.193, on which a crew ran its tools without a single policy check.- Rerunning the test against the fixes found one more bypass: the MCP gateway checked a model-supplied
domainargument instead of the host of the URL the tool would fetch. - Six more medium-severity problems, among them: URL-only network checks ignored the URL; the lifetime decision counters lost the counts of pruned audit archives;
agentguard auditshowed the oldest entries instead of the newest; three MCP file-write tools passed the default policy; and the custom-tool snippet in two guides made the policy fail to load.
What changed
Shell commands are checked one command at a time
A command that contains shell syntax (;, &&, ||, |, &, a line break, $( ), backticks, a redirection) is split into the simple commands a shell would run, and each one must pass your rules; the most severe verdict wins. Redirection targets are checked against your filesystem rules. Whole-command deny and approval rules still run first, and a command with no shell syntax is matched exactly as before.
| Command, with the default policy | 1.1.x | 1.2.0 |
|---|---|---|
ls /tmp; rm -rf / |
ALLOW | REQUIRE_APPROVAL |
ls /tmp && sudo rm -rf / |
ALLOW | REQUIRE_APPROVAL |
echo x > /etc/passwd |
ALLOW | DENY |
cat README.md \| head -5 |
ALLOW | DENY: no rule allows head |
git status && git diff |
ALLOW | ALLOW |
A pipeline is now allowed only when every command in it is, so add allow rules for the commands your agents chain. See Compound shell commands.
Policies load and match the way they read
- Rule blocks for the same scope are merged at load, with a warning. Two such blocks with different rate or cost limits are a load error.
- Likely-misspelled scope names warn (
scope "shel" … did you mean "shell"?), andagentguard validate --strictfails on any warning. url-only network and browser checks use the URL's host, as the policy reference always said.https://api.github.com@evil.com/is checked asevil.com.- The MCP gateway checks the URL's host. A
domainorhostargument next to aurlno longer stands in for it, so a model can't pair an allow-listed domain with a URL on another host. The Python MCP adapter is fixed the same way.
Secrets are masked in the audit trail
serve --audit-redact, on by default, masks keys, tokens, passwords, JWTs, private keys and credential headers before they reach the audit log, GET /v1/audit, the live stream, the dashboard and the pending-approvals list. It uses the same patterns as notifications, which gain sk-… API keys, Google keys, all GitHub token types, JWTs, PEM keys and Authorization headers, plus your policy's extra_patterns. The work happens in the audit workers, not on the /v1/check path. --audit-redact=false turns it off.
Audit and operations
agentguard auditshows the newest entries first (--order ascfor the old order), and so does the dashboard's history.GET /v1/auditgainsorder=asc|desc; its default is unchanged.- Decision counters survive archive pruning: the replay checkpoint is rewritten on every rotation and at shutdown.
serve --bind <host>keeps a keyed server on one address, such as127.0.0.1behind a reverse proxy on the same host. A non-loopback--bindwithout--api-keyrefuses to start.agentguard --versionworks like the other two binaries.
Default policy
find … -exec, -ok and -delete require approval. The filesystem MCP server's edit_file, move_file and create_directory tools are denied like write_file.
Python SDK
- The CrewAI adapter requires CrewAI 1.0+ and refuses older versions, on which it couldn't gate crew tool calls.
[all]now resolves to CrewAI 1.15, browser-use 0.11, LangChain 1.4 and MCP 1.28 with a cleanpip check. - The
mcpextra allows MCP 2.x. agentguard.__version__is new.
CI
The test_at_* suites (a real agent loop, the real LLM proxy, the MCP gateway against a real server) run in CI for the first time, and a new job installs [all] fresh and runs the whole Python suite.
Breaking changes
None in the public API. No field, route, flag, subcommand or schema version was removed or changed; everything new is additive.
The security fixes change behaviour:
- Shell chains, pipelines and redirections are checked command by command, so some that 1.1.x allowed are now denied or sent to approval.
- A second block for a scope now applies. Two blocks with different rate or cost limits make the policy fail to load.
url-only network and browser checks can be allowed where 1.1.x denied them, and MCP gateway calls with both aurland adomainargument are checked against the URL's host.- Audit content is masked by default, and
agentguard auditlists newest first. - The CrewAI adapter needs CrewAI 1.0+.
Upgrade notes
- Run
agentguard validate --strict --policy <your policy>with the 1.2.0 binary. - Replay recent shell ALLOWs from your audit log through
agentguard check --batchto see which chains 1.2.0 would stop, and add allow rules for the ones you want. - Swap the binaries and SDKs. Nothing on disk changes format, and rolling back to 1.1.x is safe, but it brings back the bypasses.
Details: MIGRATION.md § v1.1.x → v1.2.0 (github.com).
Get started
:::bash
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard@v1.2.0
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-mcp-gateway@v1.2.0
go install github.com/Caua-ferraz/AgentGuard/cmd/agentguard-llm-proxy@v1.2.0
pip install --upgrade "agentguardproxy==1.2.0"
npm install @lictorate/agentguard@1.2.0
# Docker: no image is published; build one from the repository's Dockerfile
docker build -t agentguard:1.2.0 .
Full change list: CHANGELOG.md § 1.2.0 (github.com).