AgentSeal
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, Mac, Web, Windows

Summary
AgentSeal is an open-source security scanner and toolkit for checking AI agent prompts, MCP servers, and related configurations. Its scan command uses adversarial probes to look for prompt extraction and instruction-injection weaknesses. Guard scans agent configurations and skill files on a machine, while Watch tracks those files and MCP configurations for changes. Scan-MCP runs servers in a sandbox and tests tool behavior with adversarial inputs; OAuth is supported for authenticated remote servers. The CLI supports listed providers including Ollama, OpenAI, Anthropic Claude, Google Gemini, and compatible OpenAI chat API endpoints. It can also run offline with a local Ollama model, with no network calls or telemetry according to the site. The dashboard includes scan results, prompt management, security monitoring, and GitHub integration settings. CI output options include SARIF 2.1.0, JUnit XML, GitHub Actions summaries, and policy rules for pull-request gating. The free plan costs 0.00 USD and includes 30 basic probes, the MCP registry, Guard, and Watch. CLI installation requires Python 3.10 or higher; an npm wrapper is also available.
Who it is for
AgentSeal suits teams assessing prompt and MCP-related security, including those integrating scans into CI. Its offline CLI option may suit users working with a local Ollama model.
What is good
- Scans prompts for extraction and injection weaknesses.
- Guard and Watch check local agent-related files.
- MCP scanning uses sandboxing and supports OAuth.
- CLI can run offline with local Ollama.
- CI output includes SARIF, JUnit XML, and GitHub summaries.
What to know first
- CLI requires Python 3.10 or higher.
- Free plan includes 30 basic probes.
- Pro plan price is not listed.
Everything Xiaomi review
AgentSeal: the full review
AgentSeal combines prompt testing, MCP scanning, and configuration monitoring with CI-oriented reporting. The free plan provides 30 basic probes; the CLI requires Python 3.10 or higher.
Overview
AgentSeal is an open-source security scanner and toolkit for evaluating AI agent prompts, checking MCP servers and finding vulnerabilities in agent setups. It combines adversarial scans with ongoing monitoring: users can test prompts for extraction or injection risks, inspect local agent configurations and skill files, and monitor those files and MCP configurations for changes.
The product includes a command-line interface and a web dashboard. The dashboard provides scan results, prompt management, security monitoring and GitHub integration settings. AgentSeal is freemium, with a free plan and a Pro plan whose price is not listed. Readers comparing products in this area can browse AI Red Teaming Tools.
Key features
Prompt and agent checks
The scan command runs adversarial probes against system prompts to look for extraction and instruction-injection weaknesses. The FAQ describes 311 probes covering extraction, injection, MCP tool poisoning, RAG poisoning and multimodal attacks. The free plan includes 30 basic probes; the 311-probe coverage is associated with Pro.
Guard scans agent configurations and skill files on a machine. Watch monitors those files and MCP configurations for changes, supporting continuous monitoring alongside individual scans.
MCP server scanning
Scan-MCP runs MCP servers in a sandbox and tests tool behavior using adversarial payloads. It supports OAuth for authenticated remote servers. Separately, AgentSeal's MCP registry says that each server goes through a seven-stage security pipeline before listing, including sandboxing and probing.
Provider and privacy options
The site lists support for Ollama, OpenAI, Anthropic Claude, OpenRouter, Google Gemini, DeepSeek, Groq, Together AI, LM Studio, llama.cpp, vLLM and compatible OpenAI chat API endpoints. The CLI can run fully offline with a local Ollama model; the site says this mode makes no network calls and sends no telemetry.
AgentSeal says prompts travel directly from the CLI to the user's LLM provider. Prompts and model configurations synced to the dashboard are encrypted at rest with Fernet (AES-256).
Reports and automation
For CI workflows, AgentSeal supports SARIF 2.1.0, JUnit XML, GitHub Actions summaries and policy-as-code rules for gating pull requests. Report formats also include JSON and PDF. The available attack categories include prompt extraction, instruction injection, data exfiltration and MCP tool poisoning; target systems include system prompts, AI agents, HTTP endpoints, MCP servers, RAG pipelines and multimodal systems.
Pricing
AgentSeal offers a free plan and a Pro plan. The free plan costs 0.00 USD per free and includes 30 basic probes, the MCP registry, Guard and Watch. The Pro plan's price is not listed; its stated features include 311 probes, runtime MCP scanning with OAuth, PDF export and the dashboard.
Platforms
AgentSeal is listed for API, Linux, macOS, web and Windows. The CLI is installable with pip, and an npm wrapper is available for Node projects and CI pipelines. The CLI requires Python 3.10 or higher; the npm wrapper runs the Python CLI.
Who it's for
AgentSeal is aimed at people responsible for the security of AI agents, prompts and MCP servers, particularly those who need both adversarial checks and ongoing monitoring. Its CLI, local Ollama option, CI output formats and pull-request gating rules may suit teams incorporating checks into development workflows. The dashboard adds centralized scan results, prompt management, monitoring and GitHub integration settings.
The free plan offers a way to start with basic probes and local monitoring tools. Teams needing the full 311-probe coverage, OAuth-enabled runtime MCP scanning, PDF exports or dashboard access should note that these features are listed under Pro, for which no price is provided.
Pros and cons
Pros
- Combines prompt probing, local configuration checks, MCP server testing and continuous monitoring.
- Supports offline CLI use with a local Ollama model, according to the site.
- Provides SARIF, JUnit XML, JSON, PDF and GitHub Actions summary reporting, with policy rules for pull-request gating.
- Offers a free plan with 30 basic probes, the MCP registry, Guard and Watch.
Cons
- The listed free plan includes 30 basic probes, while the 311-probe coverage is associated with Pro.
- The Pro price is not listed, making it difficult to assess the cost of its additional features from the available information.
- The npm wrapper depends on the Python CLI, which requires Python 3.10 or higher.
Alternatives
Other tools to consider include OpenSecureAI Scanner, Promptfoo, RedAmon, F5 BIG-IP APM, NVADER, ProofLayer, Confident AI and Darkhunt AI Security.
Verdict
AgentSeal brings together prompt testing, machine-local agent checks, MCP server scanning and continuous monitoring, with options for offline CLI use and CI integration. Its free plan includes a useful set of basic tools, while several advanced capabilities—including the broader probe coverage and runtime MCP scanning with OAuth—are assigned to Pro. Because the Pro price is not listed, prospective users should weigh those plan boundaries against their requirements before choosing it.
AgentSeal plans and pricing
All plansCompared on AI red teaming tools
- Free plan
- Yesagentseal.org
- Attack categories
- prompt extraction; instruction injection; data exfiltration; MCP tool poisoning; RAG poisoning; multimodal attacks; behavioral genome testingagentseal.org
- Target systems
- system prompts; AI agents; HTTP endpoints; MCP servers; RAG pipelines; multimodal AI systemsagentseal.org
- Automation level
- continuousagentseal.org
- Deployment
- hybridagentseal.org
- Continuous monitoring
- Yesagentseal.org
- Report exports
- JSON; SARIF 2.1.0; JUnit XML; PDF; GitHub Actions step summaryagentseal.org
Facts
- Purpose
- AgentSeal is an open-source security scanner and toolkit for testing AI agent prompts, auditing MCP servers, and detecting agent vulnerabilities.agentseal.org · 30 Sept 2026
- Prompt testing
- Its scan command runs adversarial probes against system prompts to detect extraction and injection vulnerabilities.agentseal.org · 30 Sept 2026
- Machine protection
- Guard scans agent configurations and skill files on a machine, while Watch monitors those files and MCP configs for changes.agentseal.org · 30 Sept 2026
- MCP scanning
- Scan-MCP runs MCP servers in a sandbox and tests tool behavior with adversarial payloads; OAuth is supported for authenticated remote servers.agentseal.org · 30 Sept 2026
- LLM providers
- The site lists Ollama, OpenAI, Anthropic Claude, OpenRouter, Google Gemini, DeepSeek, Groq, Together AI, LM Studio, llama.cpp, vLLM, and compatible OpenAI chat API endpoints.agentseal.org · 30 Sept 2026
- Privacy
- The site says prompts go directly from the CLI to the user's LLM provider, and dashboard-synced prompts and model configurations are encrypted at rest with Fernet (AES-256).agentseal.org · 30 Sept 2026
- Offline use
- The CLI can run fully offline with a local Ollama model, with zero network calls and zero telemetry, according to the site.agentseal.org · 30 Sept 2026
- CI integrations
- AgentSeal supports SARIF 2.1.0, JUnit XML, GitHub Actions summaries, and policy-as-code rules for gating pull requests.agentseal.org · 30 Sept 2026
- Security registry
- The MCP registry page says each server passes through a seven-stage security pipeline before it is listed, including sandboxing and probing.agentseal.org · 30 Sept 2026
- Scan coverage
- The FAQ describes 311 probes across extraction, injection, MCP tool poisoning, RAG poisoning, and multimodal attacks.agentseal.org · 30 Sept 2026
- Installation
- The CLI is installable with pip, and the site also provides an npm wrapper for Node projects and CI pipelines.agentseal.org · 30 Sept 2026
- Requirements
- The installation page requires Python 3.10 or higher for the CLI, and says the npm wrapper shells out to the Python CLI.agentseal.org · 30 Sept 2026
- Dashboard
- The dashboard provides scan results, prompt management, security monitoring, and GitHub integration settings.agentseal.org · 30 Sept 2026
- Support
- The contact page says the team typically responds within 24 hours and provides an email address for urgent matters.agentseal.org · 30 Sept 2026
Best AgentSeal alternatives
See all 12Where it ranks on Everything Xiaomi
Is AgentSeal yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- agentseal.org· checked 30 Sept 2026
- agentseal.org/docs· checked 30 Sept 2026
- agentseal.org/docs/installation· checked 30 Sept 2026
- agentseal.org/docs/dashboard· checked 30 Sept 2026
- agentseal.org/contact· checked 30 Sept 2026


