Your AI agent runs third-party skills and MCP servers with full access to your files, keys and shell — no sandbox, no review. I scanned 96,096 published skills; 751 were malicious. PanGuard vets a skill before you install it, scans what you already have, and blocks hijack attempts at runtime. Free, MIT, fully on-device. Powered by 768 open ATR rules, already merged into Microsoft, Cisco, MISP and OWASP tooling. One command: npm install -g panguard && pga up
Open source and MIT licensed for something guarding your AI agent's shell access is exactly the right call - I don't want to trust a closed-source binary with that. The 751-malicious-out-of-96k-skills number is a great transparency move too.
What needs improvement
Would like to see clearer docs on how the 768 ATR rules get updated over time - is that a community-driven ruleset or maintained solo, since that affects how fast it keeps up with new attack patterns.