No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by openguardrails · MCP Server · ★ 360
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is agentfw safe to install? View the security audit →
agentfw The local firewall for AI agents: route and repair them, and keep your secrets off the model, the API relay, and the supply chain. A tiny local proxy on the wire between your agents and the LLMs they call — practical features and security in one place, no framework and no telemetry. taps the wire between your coding agents (Claude Code, Codex, OpenClaw, Hermes, Claude Desktop — anything that calls an LLM or speaks MCP) and the providers they reach. From that one vantage point it does useful work and keeps the traffic safe, without switching agents, adopting a framework, or sending anything to the cloud. Practical See every model call and tool result your fleet makes — live, in one place. Route & combine — point any agent at any model, with failover chains and capability companions; auto-route Claude Code's parallel subagents to a cheaper model while the planner stays on Opus. Repair (emerging) — spot a Hermes/OpenClaw setup a bad upgrade left unstartable and put its config back, format-preserving, with per-edit backups.
| Stars | 360 |
| Forks | 58 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 66.782390563729/100 |
| Open Issues | 1 |
| Last Updated | 2026-06-11 |
| Created | 2025-10-22 |
| Platforms | claude-code, mcp, node |
| Est. Tokens | ~42k |
These tools work well together with agentfw for enhanced workflows:
Looking for a agentfw alternative? If you're comparing agentfw with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Local-first LLM proxy that meters what every agent run costs and kills runaways before they drain your budget.
Local gateway for Claude Code, Codex and other AI clients on macOS, Windows and Linux: switch upstreams withou
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, M
Source-available LLM router and AI cost optimizer. Routes simple prompts to cheap or local models and complex
Open-source LLM router & AI cost optimizer. Routes simple prompts to cheap/local models, complex ones to premi
Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (
Explore other popular mcp server tools:
agentfw is The local firewall for AI agents — keep your secrets off the model, the API relay, and the supply chain. Local credential masking, per-route model routing, and security detectors on the wire. Free & f. It is categorized as a MCP Server with 360 GitHub stars.
agentfw is primarily written in TypeScript. It covers topics such as agent-firewall, ai-agent-security, claude-code.
You can find installation instructions and usage details in the agentfw GitHub repository at github.com/openguardrails/agentfw. The project has 360 stars and 58 forks, indicating an active community.
agentfw is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to agentfw on Agent Skills Hub include proxy, ThinkWatch-Lite, hol-guard. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: