Beyond Regex: Building Detection Rules for AI Agent Vulnerabilities
When I started building has 28 samples:
- ASI01 (6 samples): 100% detection
- ASI02 (5 samples): 100% detection
- ASI03 (4 samples): 100% detection
- ASI07 (6 samples): 100% detection
- ASI10 (5 samples): 100% detection
- Clean (2 samples): 0% false positives
What's Next
AST-based taint tracking for Python and JavaScript
Language support: Rust, Go, Java
GitHub Code Scanning integration via SARIF
MCP server mode for real-time scanning in AI coding assistants
Semantic injection detection -- understanding prompt structure, not just string patterns
The long-term goal is simple: make AI agent code as auditable as web application code. We have Semgrep for web apps. We need AgentGuard for agent apps.
AgentGuard is MIT-licensed and open source. Install with pip install dfx-agentguard.
SOCIAL SHARE CARD GENERATOR