What changed
Aguara has been released as an open-source security engine focused on identifying risks within AI agent configurations and software supply chains. The tool is designed to operate locally, meaning it does not rely on Software-as-a-Service (SaaS) platforms or make external Large Language Model (LLM) calls, enhancing privacy and control for users. It scans for a range of security threats including prompt injection, risks associated with Multi-Cloud Platform (MCP) configurations, tool poisoning, unsafe GitHub Actions, secret exfiltration, and compromised packages. Aguara supports a wide array of package ecosystems, including npm, pnpm, PyPI, Go, Rust, PHP, Ruby, Java, and .NET.
The latest release, v0.28.0, introduces changes to how trust boundaries are handled. Specifically, the audit command, CI scans, and the public scanning API now ignore target-owned exclusions and suppressions by default. This means that local scan commands are the primary way to honor project-specific policies for unfamiliar projects, using the --project-policy ignore flag. Older releases might have trusted repository-owned policies, so users integrating Aguara into existing workflows are advised to review the upgrade notes.
Aguara's analysis capabilities extend to various aspects of a project:
Package and Dependency Analysis
Aguara inspects resolved dependencies using lockfiles without needing to install them. It supports lockfiles from npm (including package-lock.json, pnpm-lock.yaml, yarn.lock, bun.lock), PyPI (installed site-packages), Go (go.sum, go.mod), Rust (Cargo.lock), PHP (composer.lock), Ruby (Gemfile.lock), Java (pom.xml, Gradle lockfiles), and .NET (packages.lock.json). This feature focuses on detecting known-malicious packages based on advisories, rather than comprehensive CVE coverage. It handles exact version matching and advisories affecting package ranges, with specific support for npm semver. Limitations include file size limits (50 MiB) for lockfiles and dependency manifests, and nesting limits (128 levels) for legacy package-lock.json files.
Agent Behavior and Configuration Scanning
The tool analyzes agent instructions, tool configurations, and host settings for risky patterns. This includes detecting prompt injection attempts, suspicious requests for secrets or execution, and configurations that could lead to tool poisoning. It also scans MCP configurations for risky tool launches, embedded credentials, and specific configuration patterns. For agent host settings, it looks for broad command approvals, fetch-and-execute hooks, and code-injection vulnerabilities in files like .claude/settings.json and settings.local.json.
Threat Intelligence
Aguara incorporates an advisory snapshot sourced from OSV (Open Source Vulnerability database), including OpenSSF Malicious Packages, and manually curated incident records. It filters OSV data to focus on malicious packages, not the entire CVE database. Intelligence updates are explicit network operations, and checks can utilize a verified local cache offline. Signature verification for intelligence bundles is standard, with an insecure option available for specific scenarios.
Why it matters for builders
For developers working with AI agents or integrating external code, Aguara provides a critical layer of security analysis. It helps mitigate risks associated with prompt injection, which can manipulate agent behavior, and tool poisoning, where malicious code is disguised as a legitimate tool. By scanning dependencies, it addresses the common vulnerability of compromised packages entering the software supply chain.
The tool's local-first operation is a significant advantage, ensuring that sensitive code and configurations are not uploaded to external servers, which is crucial for maintaining intellectual property and data privacy. This approach allows builders to integrate security checks directly into their development workflows without external dependencies or privacy concerns.
Practical impact
Builders can integrate Aguara into their CI/CD pipelines to automate security checks on code changes and new dependencies. The command-line interface, with commands like aguara audit . for a comprehensive project scan or aguara scan ./skills/ for agent-specific components, allows for flexible integration. Developers can start by installing the latest release using the provided curl script, ensuring the binary is added to their PATH. Reviewing the findings from aguara audit . before installing dependencies or running CI jobs is recommended. For those using specific agent frameworks, scanning agent instructions and tool configurations with aguara scan can prevent immediate security breaches.
Caveats and source limits
The source material indicates that Aguara performs malicious-package detection, not comprehensive CVE coverage. While it identifies risky configurations and behaviors, it does not guarantee the absence of all security risks, and false positives are possible. The effectiveness of dependency scanning is dependent on the completeness of the lockfiles and the available intelligence snapshot. The upgrade notes for v0.28.0 highlight a change in how exclusions and suppressions are handled, which may require adjustments for existing integrations. The source does not provide details on performance benchmarks or specific pricing, as it is an open-source project.
Sources
Claim check: 6/6 supported claims - 6 evidence links - 100% avg confidence
- Aguara is an open-source security scanner for AI agents and software supply chains.supported - github.com
- Aguara detects prompt injection, MCP risks, tool poisoning, unsafe GitHub Actions, secret exfiltration, and compromised packages.supported - github.com
- Aguara supports package ecosystems including npm, pnpm, PyPI, Go, Rust, PHP, Ruby, Java, and .NET.supported - github.com
- Aguara operates locally, without requiring SaaS or LLM calls.supported - github.com
- Aguara v0.28.0 changes trust boundary handling to ignore target-owned exclusions and suppressions by default for audit, CI scans, and public scanning API.supported - github.com
- Aguara uses an advisory snapshot sourced from OSV and OpenSSF Malicious Packages for threat intelligence.supported - github.com
Caveats
- Single-source caution: verify critical details at the linked source.
Radar score 79/100 - how it was calculated
- Reliability 82: GitHub metadata supports source trust
- Freshness 8: Fresh GitHub release date
- Novelty 77: Fresh GitHub release
- Technical 89: Repository technical metadata
- Developer 96: Developer tooling signals
- Ecosystem 72: Fresh GitHub release
- Confidence 100: Claims have reliable evidence