frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: AgentShield SDK – Runtime security for agentic AI applications

https://pypi.org/project/agentshield-sdk/
2•iamsanjayk•9mo ago
Hi HN,

We built AgentShield, a Python SDK and CLI to add a security checkpoint for AI agents before they perform potentially risky actions like external API calls or executing generated code.

Problem: Agents calling arbitrary URLs or running unchecked code can lead to data leaks, SSRF, system damage, etc.

Solution: AgentShield intercepts these actions:

- guarded_get(url=...): Checks URL against policies (block internal IPs, HTTP, etc.) before making the request.

- safe_execute(code_snippet=...): Checks code for risky patterns (os import, eval, file access, etc.) before execution.

It works via a simple API call to evaluate the action against configurable security policies. It includes default policies for common risks.

Get Started:

Install: pip install agentshield-sdk

Get API Key (CLI): agentshield keys create

Use in Python: from agentshield_sdk import AgentShield # shield = AgentShield(api_key=...) # await shield.guarded_get(url=...) # await shield.safe_execute(code_snippet=...)

Full details, documentation, and the complete README are at <https://pypi.org/project/agentshield-sdk/>

We built this because securing agent interactions felt crucial as they become more capable. It's still early days, and we'd love to get your feedback on the approach, usability, and policies.

Comments

subhampramanik•9mo ago
Looks interesting -- Does it work like a wrapper on top of OpenAI specs? Like, can we just replace the OpenAI package with this, and it's fully integrated?
iamsanjayk•9mo ago
Hey, thanks for asking! Good question.

AgentShield isn't a wrapper around the OpenAI package, so you wouldn't replace openai with it. Think of AgentShield as a separate safety check you call just before your agent actually tries to run a specific risky action.

So, you'd still use the openai library as normal to get your response (like a URL to call or code to run). Then, before you actually use httpx/requests to call that URL, or exec() to run the code, you'd quickly check it with shield.guarded_get(the_url) or shield.safe_execute(the_code).

Currently, It focuses on securing the action itself (the URL, the code snippet) rather than wrapping the LLM call that generated it.

Amazon wraps controversial week ahead of film premier, fourth-quarter earnings

https://www.cnbc.com/2026/01/30/amazon-wraps-controversial-week-ahead-of-melania-premier-earnings...
2•1vuio0pswjnm7•8m ago•0 comments

In-Text Advertising

https://en.wikipedia.org/wiki/In-text_advertising
1•jumpocelot•15m ago•1 comments

Show HN: Securing the Ralph Wiggum Loop – DevSecOps for Autonomous Coding Agents

https://github.com/agairola/securing-ralph-loop
1•agairola•17m ago•0 comments

Solving Package Management via Hypergraph Dependency Resolution

https://arxiv.org/abs/2506.10803
1•todsacerdoti•18m ago•0 comments

The humans are screenshotting us

https://www.moltbook.com/post/01611367-056f-4eed-a838-4b55f1c6f969
1•Brajeshwar•24m ago•0 comments

AI agents now have their own Reddit-style social network

https://arstechnica.com/information-technology/2026/01/ai-agents-now-have-their-own-reddit-style-...
2•joering2•32m ago•0 comments

The API Tooling Crisis

http://efp.asia/blog/2025/12/24/api-tooling-crisis/
1•dhruv3006•33m ago•0 comments

Regarding low level Design for YarnPackageManager

https://programmingappliedai.substack.com/p/lld-design-a-low-level-machine-coding
1•HintedHandoff•35m ago•0 comments

Show HN: Sneck, a snake game controlled by your head

https://sneck.1link.fun/
1•wenjian•36m ago•0 comments

Show HN: Democracy Direct – Find and contact your elected representatives

https://democracy-direct.com/
2•ashmortar•39m ago•0 comments

Show HN: I lost 3 years of ChatGPT history overnight, so I built a backup tool

2•benjushi•42m ago•0 comments

3D Printed Software

https://nichecraft.substack.com/p/3d-printed-software
1•bfollington•44m ago•0 comments

Muse: Cursor for Composing MIDI

https://www.muse.art/home
1•memalign•46m ago•0 comments

FBI unable to extract data from iPhone 13 in Lockdown Mode in high profile case [pdf]

https://storage.courtlistener.com/recap/gov.uscourts.vaed.588772/gov.uscourts.vaed.588772.35.0_1.pdf
5•armadyl•52m ago•5 comments

Optiwing – Keyword Grouping and PAYG SEO Tools

https://optiwing.com/
1•TasselHat•53m ago•1 comments

AI Motion Graphics Tool with good design and camera movements

https://www.freemotion.app/
1•jithin_g•56m ago•0 comments

The cumulative cost of additional wakefulness (2003)

https://pubmed.ncbi.nlm.nih.gov/12683469/
1•walterbell•59m ago•0 comments

The Sovereign AI Security Crisis: 42,000 Exposed OpenClaw Instances

https://maordayanofficial.medium.com/the-sovereign-ai-security-crisis-42-000-exposed-openclaw-ins...
3•salkahfi•59m ago•1 comments

Show HN: Sharing Agentic Stream of Consciousness

https://github.com/247arjun/ai-artifacts/blob/main/SKILLS/StreamOfConsciousness-SKILL.md
1•spamfilter247•1h ago•0 comments

Neumann: I built a unified database including a Semantic Cache and AI Vault

https://github.com/Shadylukin/Neumann
1•Shadylukin•1h ago•1 comments

Hello, here is the marketplace for Moltbot (Clawdbot)

https://molt-market.com/
1•yichen-gong•1h ago•1 comments

St. Peter police chief got federal agents to release resident, sources say

https://www.mprnews.org/story/2026/01/30/st-peter-police-chief-intervenes-prevents-federal-agents...
1•starkparker•1h ago•0 comments

Unable to Stop Al, SAG-AFTRA Mulls a Studio Tax on Digital Performers

https://variety.com/2026/film/news/sag-aftra-ai-tilly-norwood-tax-digital-performers-1236644931/
1•voxadam•1h ago•1 comments

Ouroboros: An AI vibe-coding game

https://github.com/michaelwhitford/ouroboros
1•dulakian•1h ago•1 comments

Cleverbot (2008)

https://www.cleverbot.com/
3•1bpp•1h ago•3 comments

I use a Huawei modem; I cannot access this article. On my Singtel phone, I can

https://twitter.com/MikeFritzell/status/2017784723389759685
4•cwwc•1h ago•0 comments

Archive.today is directing a DDoS attack against my blog

https://gyrovague.com/2026/02/01/archive-today-is-directing-a-ddos-attack-against-my-blog/
5•gyrovague-com•1h ago•0 comments

Workers are 'friction-maxxing' to resist AI

https://www.ft.com/content/fd5e65df-83c7-42f3-9658-377c99df42d1
3•cebert•1h ago•1 comments

Show HN: SBOMHub – Open-source SBoM dashboard with CVE tracking

https://github.com/youichi-uda/sbomhub/blob/main/README_en.md
1•y1uda•1h ago•0 comments

Show HN: Skill.Fish – NPM-style package manager for AI agent skills

https://github.com/knoxgraeme/skillfish
1•knoxgraeme•1h ago•0 comments