MCP tool protection
Detects and blocks malicious MCP tools (tool poisoning) before an agent can call them.
Bitdefender AI Guardian is a security layer for autonomous AI agents on macOS. It inspects what an agent does — tool calls, file access, prompts, skills — and returns a verdict of allowed, flagged or blocked against a policy baseline you set. It targets prompt injection, MCP tool poisoning, credential leakage and unauthorised actions. Currently in open BETA.
AI Guardian is a Bitdefender security product that helps protect people and organisations from the risks of autonomous AI agents — prompt injection, unsafe tool use, data leakage, and unauthorised actions. It adds a baseline security model of policies, permissions, and auditing, guardrails for tool execution, and monitoring and response workflows.
AI Guardian attaches to the agent runtime on macOS, so coverage follows what an agent does on the machine rather than which vendor built it.
| Environment | Coverage | Notes |
|---|---|---|
| MCP clients and servers | Supported in BETA | Tool inspection at the Model Context Protocol layer |
| Agent skills and plugins | Supported in BETA | Skill vetting before a skill executes |
| CLI coding agents | Supported in BETA | Claude Code2.1.121+andOpenClaw2026.6.6+ |
| IDE-embedded agents | Coming soon | Editor assistants with tool access |
| macOS | Supported in BETA | Initial platform |
| Windows and Linux | Planned | Not available in BETA |
AI Guardian watches how an AI agent behaves and secures six of the highest-risk areas in agentic workflows. Each protection returns a verdict in real time.
Detects and blocks malicious MCP tools (tool poisoning) before an agent can call them.
Scans and validates agent skills before they run, so unreviewed skills don't execute silently.
Catches attempts to hijack an agent through crafted inputs and hidden instructions.
Watches every tool an agent invokes in real time, building an auditable record of actions.
Detects exposure of secrets such as API keys before they leave the machine.
Blocks unauthorised access to sensitive files such as SSH keys and system credentials.
AI Guardian secures the actions an AI agent takes. It is not a traditional antivirus, a network VPN, or a chatbot content filter.
AI Guardian works in three stages: you set a policy baseline, it enforces guardrails at execution, and it monitors and responds to what happens.
Define what agents are allowed to do — permissions, policies, and auditing for tools, files, and actions.
Every tool call and action is checked against policy in real time and gets a verdict: allowed, flagged, or blocked.
Security events feed monitoring and response workflows, so teams can review what agents did and why.
The table compares how five common agent events play out on an unprotected machine and on one running AI Guardian.
| Agent event | Without AI Guardian | With AI Guardian |
|---|---|---|
| Prompt injection | Agent may follow the injected instruction | Flagged or blocked before it acts |
| Malicious MCP tool | Tool runs and can steer the agent | Blocked before the agent calls it |
| API key in a prompt | Secret can leave the machine | Credential exposure is detected |
| Access to ~/.ssh/id_rsa | Sensitive files readable by the agent | Unauthorised access is blocked |
| Unreviewed skill | Runs without inspection | Vetted before it runs |
This table maps AI Guardian's protections to the risk categories the industry is standardising on for agentic applications.
| Risk category | AI Guardian coverage |
|---|---|
| Prompt injection | Inspects agent inputs and actions; returns allowed, flagged or blocked |
| Tool and MCP misuse | Detects and blocks malicious or tampered MCP tools before invocation |
| Excessive or unscoped permissions | Policy baseline defines what agents may do with tools, files and actions |
| Sensitive data exposure | Detects credential and secret exposure before it leaves the machine |
| Unvetted extensions and skills | Scans and validates skills before they run |
| Unmonitored agent activity | Real-time tool-call monitoring with an auditable record |
Category naming is informed by OWASP's work on agentic-application security; the names are ours, not OWASP's published identifiers.
AI Guardian installs from a signed macOS installer and runs as a background service; the rows below list how it installs, where analysis happens, and what the BETA costs.
AI Guardian is made by Bitdefender, the company that has protected people and organisations since 2001. The figures and recognitions below describe Bitdefender the company — not the AI Guardian product, which is in BETA. Why millions trust Bitdefender →

A partnership born from a passion for high performance and technological innovation — Bitdefender supports Ferrari with Advanced Threat Intelligence to improve detection and response to cyber threats.
Learn more →




Consistently top-ranked by the world’s leading independent testing labs and tech publications.
Learn more →Heritage: AI in cybersecurity since 2008 — 70+ academic papers and 50+ researchers behind Bitdefender's AI.
Prompt injection is an attack where crafted input tricks an AI agent into following instructions it should ignore. AI Guardian inspects agent inputs and actions and returns a verdict — allowed, flagged, or blocked — so a hijacked instruction can be caught before it turns into an action.
MCP tool poisoning is when a Model Context Protocol tool is malicious or has been tampered with, so an agent that calls it can be steered into harmful behaviour. AI Guardian detects and blocks malicious MCP tools before an agent uses them.
Every agent action and tool call is checked in real time against a policy baseline. AI Guardian then returns one of three verdicts: allowed lets the action proceed, flagged surfaces it for review, and blocked stops it.
Constrain it with a policy baseline, vet the tools and skills it can reach, and monitor every call it makes. AI Guardian applies all three on macOS: it vets skills and MCP tools before execution, checks each tool call and file access against policy, and records an auditable trail of what the agent did.
No. AI Guardian is not a traditional endpoint antivirus, a network firewall or VPN, or a content filter for chatbot text. It secures the actions an agent takes — tool calls, file access, skills and prompts — which is a different layer from malware scanning.
In BETA, AI Guardian supports two agents: Claude Code 2.1.121 or newer, and OpenClaw 2026.6.6 or newer. It integrates with each through a small plugin — the OpenClaw gateway plugin and the Claude Code hook — so support is per-agent rather than automatic for anything running on the machine. It also covers MCP clients and servers, and agent skills and plugins. IDE-embedded agents are coming next; other agents are not supported yet.
AI Guardian runs on macOS at launch. Support for additional platforms is planned.
AI Guardian is free during BETA. Download the macOS installer and run it — there is no waitlist and no licence key. It will stay free for early adopters after BETA.
Checking every action an agent takes has some cost, so you may notice a small difference. AI Guardian is built to keep it minimal.
AI Guardian is in open BETA on macOS. Download the BETA and secure your agentic workflows.
Downloads the macOS BETA (.dmg). Free during BETA.
This site is built to be read by AI assistants, browsers, and agents. Structured, curated context is available at:
No security product guarantees complete protection. Effectiveness depends on configuration, runtime environment and the type of agents used. Features and availability may vary. Initially available on macOS, with further platforms to follow.