Why it matters
Developers building AI agents and integrating third-party code can use Aguara to proactively identify security risks before deployment. Its local-first approach ensures privacy and control, while its broad ecosystem support helps secure diverse project dependencies.

What changed

Aguara has been released as an open-source security engine focused on identifying risks within AI agent configurations and software supply chains. The tool is designed to operate locally, meaning it does not rely on Software-as-a-Service (SaaS) platforms or make external Large Language Model (LLM) calls, enhancing privacy and control for users. It scans for a range of security threats including prompt injection, risks associated with Multi-Cloud Platform (MCP) configurations, tool poisoning, unsafe GitHub Actions, secret exfiltration, and compromised packages. Aguara supports a wide array of package ecosystems, including npm, pnpm, PyPI, Go, Rust, PHP, Ruby, Java, and .NET.

The latest release, v0.28.0, introduces changes to how trust boundaries are handled. Specifically, the audit command, CI scans, and the public scanning API now ignore target-owned exclusions and suppressions by default. This means that local scan commands are the primary way to honor project-specific policies for unfamiliar projects, using the --project-policy ignore flag. Older releases might have trusted repository-owned policies, so users integrating Aguara into existing workflows are advised to review the upgrade notes.

Aguara's analysis capabilities extend to various aspects of a project:

Package and Dependency Analysis

Aguara inspects resolved dependencies using lockfiles without needing to install them. It supports lockfiles from npm (including package-lock.json, pnpm-lock.yaml, yarn.lock, bun.lock), PyPI (installed site-packages), Go (go.sum, go.mod), Rust (Cargo.lock), PHP (composer.lock), Ruby (Gemfile.lock), Java (pom.xml, Gradle lockfiles), and .NET (packages.lock.json). This feature focuses on detecting known-malicious packages based on advisories, rather than comprehensive CVE coverage. It handles exact version matching and advisories affecting package ranges, with specific support for npm semver. Limitations include file size limits (50 MiB) for lockfiles and dependency manifests, and nesting limits (128 levels) for legacy package-lock.json files.

Agent Behavior and Configuration Scanning

The tool analyzes agent instructions, tool configurations, and host settings for risky patterns. This includes detecting prompt injection attempts, suspicious requests for secrets or execution, and configurations that could lead to tool poisoning. It also scans MCP configurations for risky tool launches, embedded credentials, and specific configuration patterns. For agent host settings, it looks for broad command approvals, fetch-and-execute hooks, and code-injection vulnerabilities in files like .claude/settings.json and settings.local.json.

Threat Intelligence

Aguara incorporates an advisory snapshot sourced from OSV (Open Source Vulnerability database), including OpenSSF Malicious Packages, and manually curated incident records. It filters OSV data to focus on malicious packages, not the entire CVE database. Intelligence updates are explicit network operations, and checks can utilize a verified local cache offline. Signature verification for intelligence bundles is standard, with an insecure option available for specific scenarios.

Why it matters for builders

For developers working with AI agents or integrating external code, Aguara provides a critical layer of security analysis. It helps mitigate risks associated with prompt injection, which can manipulate agent behavior, and tool poisoning, where malicious code is disguised as a legitimate tool. By scanning dependencies, it addresses the common vulnerability of compromised packages entering the software supply chain.

The tool's local-first operation is a significant advantage, ensuring that sensitive code and configurations are not uploaded to external servers, which is crucial for maintaining intellectual property and data privacy. This approach allows builders to integrate security checks directly into their development workflows without external dependencies or privacy concerns.

Practical impact

Builders can integrate Aguara into their CI/CD pipelines to automate security checks on code changes and new dependencies. The command-line interface, with commands like aguara audit . for a comprehensive project scan or aguara scan ./skills/ for agent-specific components, allows for flexible integration. Developers can start by installing the latest release using the provided curl script, ensuring the binary is added to their PATH. Reviewing the findings from aguara audit . before installing dependencies or running CI jobs is recommended. For those using specific agent frameworks, scanning agent instructions and tool configurations with aguara scan can prevent immediate security breaches.

Caveats and source limits

The source material indicates that Aguara performs malicious-package detection, not comprehensive CVE coverage. While it identifies risky configurations and behaviors, it does not guarantee the absence of all security risks, and false positives are possible. The effectiveness of dependency scanning is dependent on the completeness of the lockfiles and the available intelligence snapshot. The upgrade notes for v0.28.0 highlight a change in how exclusions and suppressions are handled, which may require adjustments for existing integrations. The source does not provide details on performance benchmarks or specific pricing, as it is an open-source project.

Sources

Written with AI assistance from the linked sources; every claim below was checked against them automatically. How we produce articles.

Claim check: 6/6 supported claims - 6 evidence links - 100% avg confidence
  • Aguara is an open-source security scanner for AI agents and software supply chains.supported - github.com
  • Aguara detects prompt injection, MCP risks, tool poisoning, unsafe GitHub Actions, secret exfiltration, and compromised packages.supported - github.com
  • Aguara supports package ecosystems including npm, pnpm, PyPI, Go, Rust, PHP, Ruby, Java, and .NET.supported - github.com
  • Aguara operates locally, without requiring SaaS or LLM calls.supported - github.com
  • Aguara v0.28.0 changes trust boundary handling to ignore target-owned exclusions and suppressions by default for audit, CI scans, and public scanning API.supported - github.com
  • Aguara uses an advisory snapshot sourced from OSV and OpenSSF Malicious Packages for threat intelligence.supported - github.com

Caveats

  • Single-source caution: verify critical details at the linked source.
Radar score 79/100 - how it was calculated
Reliability82
Freshness8
Novelty77
Technical89
Developer96
Ecosystem72
Confidence100
  • Reliability 82: GitHub metadata supports source trust
  • Freshness 8: Fresh GitHub release date
  • Novelty 77: Fresh GitHub release
  • Technical 89: Repository technical metadata
  • Developer 96: Developer tooling signals
  • Ecosystem 72: Fresh GitHub release
  • Confidence 100: Claims have reliable evidence
Share
XLinkedInHacker News

Related articles

AI Coding - Sep 29, 2026Codewhale: Open-Source Terminal AI Coding AgentCodewhale is an open-source AI coding agent designed for the terminal, built with Rust. It allows users to interact with AI models for tasks like editing files and running commands directly within their project folders. The agent supports both hosted and local model integrations, offering flexibility for developers.Other - Oct 1, 2026Guardana v0.31.0: AI Security Verification ToolGuardana has released version v0.31.0, an open-source tool for AI security verification. It focuses on model artifacts, live endpoints, MCP servers, and agent traces, providing reproducible evidence for release decisions.Other - Oct 3, 2026BrowserOS: Open-Source Agentic BrowserBrowserOS is an open-source agentic browser designed as an alternative to platforms like ChatGPT Atlas and Perplexity Comet. It supports multiple operating systems and integrates with various LLM providers.Developer Tools - Sep 29, 2026Open Source AI Radar: AI Project Intelligence PlatformOpen Source AI Radar is a new intelligence platform designed to discover and analyze emerging open-source AI projects on GitHub. It utilizes a three-axis scoring system (Impact, Velocity, Health) to identify projects gaining importance, moving beyond simple star counts.AI Coding - Sep 29, 2026pi-goal-list-loop-audit: Enhanced AI Agent SupervisionDraconDev has released pi-goal-list-loop-audit (GLLA), a pi-coding-agent extension designed to supervise long-running autonomous tasks. GLLA enhances durability, recoverability, and evidence-backed completion by implementing an isolated auditor for each task's completion.AI Coding - Sep 29, 2026Soundings v0.2.0: New Codex Skills for Research and Decision-MakingIndelibleVivi has released version 0.2.0 of Soundings, a set of Codex skills designed to aid in research, creative development, and decision-making. The update introduces four distinct skills: `search` for external investigation, `study` for synthesizing information, `explore` for creative generation, and `shape` for refining choices.