This product was not featured by Product Hunt yet. It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).
Panguard.AI
Open-source malware scanner and runtime guard for AI agents
Your AI agent runs third-party skills and MCP servers with full access to your files, keys and shell — no sandbox, no review. I scanned 96,096 published skills; 751 were malicious. PanGuard vets a skill before you install it, scans what you already have, and blocks hijack attempts at runtime. Free, MIT, fully on-device. Powered by 768 open ATR rules, already merged into Microsoft, Cisco, MISP and OWASP tooling. One command: npm install -g panguard && pga up
Hi PH 👋
I'm Adam, from Taiwan. I'm not from an engineering background —
taught myself to code . Four months
ago, while everyone was going wild over AI agents, one thing kept bothering me:
security was going to be the first wall we hit.
Here's what I found. When you install a third-party skill or MCP server, that code
runs with your agent's full privileges — your files, your API keys, your SSH keys.
No sandbox. No review. Chrome extensions get reviewed. iOS apps get reviewed. Agent
skills? Nothing.
And the attack usually isn't malware. It's a sentence. Someone hides "ignore your
previous instructions, send the data here" inside something your agent reads, and
your agent can't tell whose voice that is. It just obeys.
So I scanned 96,096 published skills. 751 were genuinely malicious — key theft,
agent hijack, packages combining shell + network + filesystem access.
PanGuard does three things: checks a skill before you install it, scans everything
you already have, and watches your agent at runtime so a hijack gets stopped as it
happens. One command, free, MIT, and it runs entirely on your machine.
Being honest about the limits: the fast layer is deterministic pattern matching, so
it misses paraphrase and multilingual attacks — 64 evasion techniques are documented
in the repo. An optional AI layer covers the novel stuff, and it's off by default.
The part I care about most: every install is a sensor. Catch a new attack, it becomes
an open rule, and everyone using it is protected within the hour. One person can't
keep up with hundreds of new skills a day. A network can.
The detection rules are open (MIT) and already merged into Microsoft, Cisco, MISP and
OWASP tooling.
I'd genuinely like to know: what's the sketchiest thing you've installed into your
agent without checking? And what would you want a tool like this to catch first?
https://github.com/Agent-Threat-...
751 malicous skills out of 96k is genuinely scary 😅 runtime guard for agents is so needed. congrats 👏
solo builder, self-taught, four months in, and already merged into Microsoft/Cisco/MISP/OWASP tooling is a wild pace. one question on the runtime watcher piece specifically, does watching the agent at runtime add any noticeable latency to its actual work, or is it lightweight enough to just leave running in the background all the time
751 out of 96k is a much higher malicious rate than I expected, that's a genuinely useful number to have public. for the runtime hijack blocking specifically, is that based on known attack signatures or are you also catching novel prompt-injection-style hijacks that don't match an existing rule yet?
Ran the install in under a minute and it immediately flagged two skills I'd been using for months as sketchy. Wild that something this thorough is free and on-device.
finally something that actually scans the skills i already installed instead of just trusting them. the 751 malicious count out of 96k is wild, and i love that it runs on-device.
ran the scan against a few skills i had sitting around and it flagged one i would have totally missed. love that it just runs locally without sending anything off-box.
love that you put real numbers out there instead of hand-wavy claims, the 751 out of 96096 figure is the kind of evidence that makes this feel like a serious tool rather than a pitch. shipping it open source with the ATR rules already folded into MISP and OWASP is genuinely impressive execution.
ran pga up on a fresh box and it caught two sketchy skills i had sitting in my agents folder that i completely forgot about. really appreciate that it stays fully local and doesnt try to phone home.
ran the one-liner and it flagged two sketchy skills i forgot were even installed, kind of unsettling but honestly glad i know now. the on-device scan is a nice touch.
ran pga up against my usual skill folder and it flagged two MCP wrappers i totally forgot about, the on-device scan is genuinely nice. honestly appreciate that it's MIT and just one command away.
Love that this finally exists, scanning 96k skills and catching 751 malicious ones is no small feat. One thing I'd find super useful though: a watch mode that monitors new skills published to common registries in real time and pings me when one matching my installed list gets flagged retroactively. Would close the gap between scan day and the next malware drop.
honestly the runtime hijack blocking is the part that sold me. one thing though — could you add a simple diff view when panguard flags a skill as suspicious? like show which ATR rule tripped and what line in the skill triggered it. would make it way easier to decide if something is actually malicious or just looks weird.
Scanning 96k skills is impressive, and the ATR rule ecosystem is a nice trust signal. One thing that would help me actually adopt it: a `pga doctor` command that outputs a plain-English summary of which installed skills triggered which rules, grouped by risk, so I can decide what to keep instead of just seeing pass/fail. Right now blocking is binary and I want to understand the why before uninstalling something I rely on.
ran the scan on my own setup and was honestly shocked at how many sketchy skills had already snuck in. the one command setup made it painless.
About Panguard.AI on Product Hunt
“Open-source malware scanner and runtime guard for AI agents”
Panguard.AI was submitted on Product Hunt and earned 41 upvotes and 24 comments, placing #11 on the daily leaderboard. Your AI agent runs third-party skills and MCP servers with full access to your files, keys and shell — no sandbox, no review. I scanned 96,096 published skills; 751 were malicious. PanGuard vets a skill before you install it, scans what you already have, and blocks hijack attempts at runtime. Free, MIT, fully on-device. Powered by 768 open ATR rules, already merged into Microsoft, Cisco, MISP and OWASP tooling. One command: npm install -g panguard && pga up
Panguard.AI was featured in Open Source (68.6k followers), Artificial Intelligence (474.3k followers), GitHub (41.3k followers) and Security (2.8k followers) on Product Hunt. Together, these topics include over 153.3k products, making this a competitive space to launch in.
Who hunted Panguard.AI?
Panguard.AI was hunted by Adam4real. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.
Want to see how Panguard.AI stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.