Agent Plugins Marketplace
← All plugins

agentguard

v0.15.0

A security check-up for your Claude setup. Say 'set up AgentGuard' to begin; after that, just ask: 'Is my Claude setup safe?', 'Is this skill safe to install?', 'Clean up my unused skills.' Everything runs on your machine; nothing is uploaded. Security antivirus for Claude Code environments. Audits skills, MCP servers, hooks, permission allowlists, subagents, slash commands, plugins and CLAUDE.md for prompt injection, credential exfiltration, arbitrary execution and over-broad grants — locally and offline; scanning is strictly read-only, and the one command that writes (clean) moves and never deletes. Vets a skill before you install it, and gates loads on a canonical hash.

Claude Code3 Skills

By BNB Attestation ServiceLicense: MIT0 GitHub starsUpdated 1 hour ago

Directory evidence

Runtimes
Claude Code
Parsed components
3 skill or MCP entries
Source updated
Sep 30, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install agentguard for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install agentguard-3@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/basdotio/AgentGuard

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugin/.

Plugin files

plugin/
├── .claude-plugin/plugin.json
├── skills/agentguard-audit/SKILL.md
├── skills/agentguard-gate/SKILL.md
└── skills/agentguard-vet/SKILL.md

Included Skills3

agentguard-auditskills/agentguard-audit/SKILL.md

Checks whether what you already have installed in Claude is safe. Say: 'Scan my Claude setup', 'What does EXFIL-001 mean?', 'Clean up my duplicate skills', 'Set up AgentGuard'. Audits an agent environment with AgentGuard (`aguard scan`): ~/.claude or a project's .claude, for prompt injection, credential exfiltration, arbitrary-execution grants, silent hooks and malicious skills/MCP servers/subagents/CLAUDE.md, then triages findings into a fix plan; also junk cleanup (`aguard clean`). Trigger when the user asks to scan, audit or check their agent setup or whether installed skills are safe, asks what a rule ID means (INJ-001, EXEC-001, EXFIL-002, PERM-006, HOOK-001, SUP-004, COV-000, GATE-001, ...) or why their score is what it is, wants config cleaned up, asks how to use AgentGuard (references/usage.md, no scan), wants the deeper AI check or to set up/test the LLM judge (references/llm.md), or asks in any wording to set up, install or get started with AgentGuard (references/setup.md).

agentguard-gateskills/agentguard-gate/SKILL.md

Turns on automatic protection: every skill is checked before it loads, and anything with a finding asks you first. Say: 'Turn on the gate', 'I trust this skill, stop asking'. Install, inspect, repair or remove AgentGuard's load-time gate (`aguard hook`) — a Claude Code hook that audits a skill before an agent loads it and asks the user about anything carrying a finding, and manage the hash-keyed approvals it remembers (`aguard approve` / `approvals` / `forget`). Trigger when the user wants automatic protection rather than remembering to scan, asks to install/uninstall the aguard hook or set up hook-based scanning of skills, asks why the gate is prompting (or has stopped prompting), asks to trust or untrust a skill so it stops asking, or hits a GATE-000 / GATE-001 finding.

agentguard-vetskills/agentguard-vet/SKILL.md

Checks a new skill before you install it. Say: 'I downloaded this skill, is it safe to install?' and hand over the folder or the link. Vet a single AI agent artifact with AgentGuard (`aguard check`) before it is installed, committed or trusted — one skill directory, plugin, MCP config, subagent, slash command, hook script, CLAUDE.md or loose file. Exits non-zero at or above a severity threshold, so it also drops into a git pre-commit hook or CI. Trigger when the user asks whether a specific skill/plugin/repo is safe to install, pastes or links one and asks you to review it, asks to check a downloaded or third-party skill before adding it to ~/.claude, wants a security gate in CI or pre-commit for the skills they publish, or wants an artifact's canonical hash.

Plugin manifests1

plugin/.claude-plugin/plugin.json
{
  "name": "agentguard",
  "description": "A security check-up for your Claude setup. Say 'set up AgentGuard' to begin; after that, just ask: 'Is my Claude setup safe?', 'Is this skill safe to install?', 'Clean up my unused skills.' Everything runs on your machine; nothing is uploaded. Security antivirus for Claude Code environments. Audits skills, MCP servers, hooks, permission allowlists, subagents, slash commands, plugins and CLAUDE.md for prompt injection, credential exfiltration, arbitrary execution and over-broad grants — locally and offline; scanning is strictly read-only, and the one command that writes (clean) moves and never deletes. Vets a skill before you install it, and gates loads on a canonical hash.",
  "version": "0.15.0",
  "author": {
    "name": "BNB Attestation Service"
  },
  "homepage": "https://github.com/basdotio/guard",
  "license": "MIT"
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[agentguard on Agent Plugins Marketplace](https://pluginsmp.com/plugins/agentguard-3)