agentfw — security grade SAFE, quality 67/100

Security audit verdict: SAFE · quality 67/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by openguardrails · MCP Server · ★ 360

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is agentfw safe to install? View the security audit →

About agentfw

agentfw The local firewall for AI agents: route and repair them, and keep your secrets off the model, the API relay, and the supply chain. A tiny local proxy on the wire between your agents and the LLMs they call — practical features and security in one place, no framework and no telemetry. taps the wire between your coding agents (Claude Code, Codex, OpenClaw, Hermes, Claude Desktop — anything that calls an LLM or speaks MCP) and the providers they reach. From that one vantage point it does useful work and keeps the traffic safe, without switching agents, adopting a framework, or sending anything to the cloud. Practical See every model call and tool result your fleet makes — live, in one place. Route & combine — point any agent at any model, with failover chains and capability companions; auto-route Claude Code's parallel subagents to a cheaper model while the planner stays on Opus. Repair (emerging) — spot a Hermes/OpenClaw setup a bad upgrade left unstartable and put its config back, format-preserving, with per-edit backups.

agent-firewallai-agent-securityclaude-codecredential-maskingguardrailsindirect-prompt-injectionllm-firewallllm-gatewayllm-proxylocal-first

Quick Facts

Stars360
Forks58
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score66.782390563729/100
Open Issues1
Last Updated2026-06-11
Created2025-10-22
Platformsclaude-code, mcp, node
Est. Tokens~42k

Compatible Skills

These tools work well together with agentfw for enhanced workflows:

  • NadirClaw — semantic(0.21)+complementary+rare_topics+similar_pop+shared_platform (61%)
  • NadirClaw — semantic(0.21)+complementary+rare_topics+similar_pop+shared_platform (61%)
  • ClawGuard — semantic(0.32)+complementary+rare_topics+same_lang+similar_pop+shared_platform (61%)
  • api-relay-audit — semantic(0.33)+complementary+rare_topics+similar_pop+shared_platform (60%)
  • llmgateway — semantic(0.18)+complementary+rare_topics+same_lang+similar_pop+shared_platform (60%)

agentfw alternative? Top 6 similar tools

Looking for a agentfw alternative? If you're comparing agentfw with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • proxy by RelayPlane · ⭐ 204

    Local-first LLM proxy that meters what every agent run costs and kills runaways before they drain your budget.

  • ThinkWatch-Lite by ThinkWatchProject · ⭐ 855

    Local gateway for Claude Code, Codex and other AI clients on macOS, Windows and Linux: switch upstreams withou

  • hol-guard by hashgraph-online · ⭐ 728

    Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M

  • NadirClaw by NadirRouter · ⭐ 655

    Source-available LLM router and AI cost optimizer. Routes simple prompts to cheap or local models and complex

  • NadirClaw by doramirdor · ⭐ 336

    Open-source LLM router & AI cost optimizer. Routes simple prompts to cheap/local models, complex ones to premi

  • agent-security-scanner-mcp by sinewaveai · ⭐ 121

    Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is agentfw?

agentfw is The local firewall for AI agents — keep your secrets off the model, the API relay, and the supply chain. Local credential masking, per-route model routing, and security detectors on the wire. Free & f. It is categorized as a MCP Server with 360 GitHub stars.

What programming language is agentfw written in?

agentfw is primarily written in TypeScript. It covers topics such as agent-firewall, ai-agent-security, claude-code.

How do I install or use agentfw?

You can find installation instructions and usage details in the agentfw GitHub repository at github.com/openguardrails/agentfw. The project has 360 stars and 58 forks, indicating an active community.

What license does agentfw use?

agentfw is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to agentfw?

The top alternatives to agentfw on Agent Skills Hub include proxy, ThinkWatch-Lite, hol-guard. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools