Let your AI agent read the web. Stop it before it logs in, signs up or posts.
Agent Egress Guard checks every request an agent is about to send. Reads pass. Login and sign-up forms, cloud metadata addresses and every write it does not recognise are denied, before the request leaves.
$ agent-egress-guard check https://example.com/login -X POST DENY POST https://example.com/login layer: rules rule: login $ agent-egress-guard check http://2852039166/latest/meta-data/ DENY GET http://2852039166/latest/meta-data/ layer: host list rule: 169.254.169.254 (same address, written as a number) $ agent-egress-guard check https://docs.python.org/3/ ALLOW GET https://docs.python.org/3/ $ agent-egress-guard replay 15 of the 18 steps that the full policy denies are denied here.
Four checks, in a fixed order
The same order the AI Agent Allowlist service uses. Every verdict names the layer and the rule that decided it, so you can log it, audit it and explain it.
1 · Host list
Hosts denied whatever the page. The free edition blocks the cloud metadata addresses, where agents in sandboxes look for credentials.
2 · Page types
The domain's verified login, sign-up, checkout and upload pages, from a database of 40.8 million domains. Added with an API key.
3 · URL rules
Patterns that recognise risky endpoints on any site. Free: login, sign-up and password reset. Full: 40 rules.
4 · Default
GET and HEAD pass. POST, PUT, PATCH, DELETE and every other method to an unrecognised URL are denied.
Before any check, URLs are read the way servers read them: /%6Cogin is /login, /login;jsessionid=1 is /login, and 2852039166, 0xA9FEA9FE and [::ffff:a9fe:a9fe] are all 169.254.169.254.
From nothing to a working check in four steps
Works on Windows, macOS and Linux with Python 3.8 or newer. Nothing else is installed.
Make a folder and a virtual environment
Keeps the tool separate from the rest of your Python.
mkdir egress-guard-test && cd egress-guard-test
python3 -m venv .venv
. .venv/bin/activate # Windows: .venv\Scripts\activateInstall the package
Straight from this page. The file's SHA-256 is listed under Download.
pip install https://www.aiagentallowlist.com/egress-guard/agent_egress_guard-0.2.0-py3-none-any.whl
Check a few requests
Exit code 2 means denied, so you can use it in scripts.
agent-egress-guard check https://example.com/login -X POST agent-egress-guard check https://example.com/docs agent-egress-guard check http://169.254.169.254/latest/meta-data/
Replay the 2026 incidents
24 representative requests reconstructed from public AI-agent incident disclosures. The output lists each step, its verdict and what the free edition lets through.
agent-egress-guard replay
One line for the client your agent already uses
Denied requests raise EgressDenied (HTTP clients) or are aborted (browsers and proxy). Every verdict carries the layer, rule and a note for your logs.
from agent_egress_guard import Guard guard = Guard() v = guard.check("https://example.com/wp-login.php", "POST") print(v.decision, v.layer, v.rule) # deny rules login
Needs pip install requests.
import requests from agent_egress_guard import guard_requests, EgressDenied session = guard_requests(requests.Session()) try: session.post("https://example.com/login", data={"user": "agent"}) except EgressDenied as e: print("blocked:", e.verdict.rule)
Needs pip install httpx.
import httpx from agent_egress_guard import httpx_hook client = httpx.Client(event_hooks={"request": [httpx_hook()]})
Needs pip install playwright and python -m playwright install chromium.
from playwright.sync_api import sync_playwright from agent_egress_guard import guard_playwright with sync_playwright() as p: browser = p.chromium.launch() context = browser.new_context() guard_playwright(context) # denied requests are aborted page = context.new_page() page.goto("https://example.com/")
pip install mitmproxy
mitmdump -s "$(agent-egress-guard mitm-script)"
# point the agent or container at the proxy: denied requests get a 403 with the verdict as JSONCurrent mitmproxy needs Python 3.12 or newer (its own requirement; older Pythons get a broken old version). Install both in a Python 3.12 environment.
New in 0.2.0. One policy file per agent: allowed page types, denied domains, unclassified destinations, narrow exceptions. Build one in the policy builder.
agent-egress-guard policy init --agent vendor-research --owner procurement-lead --tier 3 > vendor-research.json
agent-egress-guard policy validate vendor-research.json
agent-egress-guard policy check vendor-research.json https://example.com/login -X POST
# APPROVAL_REQUIRED rule: login (tier 3 agents route denials to their owner)from agent_egress_guard import Guard, AgentPolicy policy = AgentPolicy.load("vendor-research.json") v = policy.check(Guard(), "https://example.com/start-trial") print(v.decision) # allow, deny or approval_required
The free edition stops most writes. The full edition knows the pages.
Same code, same verdict format. Loading the full rule files and an API key is one line: Guard(rules_path=..., hosts_path=..., api_key=...).
URL rules
Free: login, sign-up, password reset. Full: 40 rules, including checkout, payment, uploads, repository writes, package publishing, wiki edits sent as GET, admin panels and CI/CD.
Host list
Free: the cloud metadata addresses. Full: 62 hosts, such as cloud consoles, package registries, paste sites, deployment APIs and webhook sinks.
Page-type database
URL patterns recognise fewer than half of real login pages; many sit on paths like /account or /mon-compte. The database lists each domain's verified login, sign-up and checkout URLs.
Nothing hidden, nothing sent home
A security tool has to be checkable. Here is what you can verify yourself.
Open source, Apache 2.0
Free for commercial use. Read every line: browse the source or download the source archive below.
Runs on your machine
Standard library only, no telemetry. The free edition makes no network calls at all; only the optional page-type database contacts our API, and only when you give it a key.
Same verdicts as production
With the full rule files loaded, the engine matched the AI Agent Allowlist service on all 726,018 real URL and method pairs we compared.
Tested, tests included
29 unit tests ship with the source, including URL-encoding, path-parameter and IP-notation tricks. Run them with python -m unittest.
Checksums on every file
Compare the SHA-256 below with sha256sum (macOS: shasum -a 256) before you install.
Who is behind it
Alpha Quantum, enterprise software since 2007. AI Agent Allowlist publishes open data on page types across 40.8 million domains.
Version 0.2.0
The package (wheel) installs with pip; the source archive contains the same code plus the tests.
Licence: Apache License 2.0 · README · Copyright 2026 Alpha Quantum
Before you install
Does it replace a firewall or a secure web gateway?
No. It decides at the level of pages and methods (may this agent submit this login form?), which network firewalls do not see. Use it next to your existing controls, inside the agent (Python hooks) or in front of it (mitmproxy).
What happens with sites the rules do not know?
Reads (GET, HEAD) pass and every other method is denied. That default alone stops most of the harmful steps in the incident replay, because they were writes.
Will it block legitimate reading?
Only pages whose URL matches a rule (login, sign-up, password reset) and the metadata addresses. Measured on real verified URLs, the full rule set matches about 0.2% of read pages, and most of those turn out to be sign-up or login pages filed under another label.
Where do the incident steps come from?
They are representative requests reconstructed from public disclosures of 2026 AI-agent incidents, grouped by scenario. See the incidents report for the sources.
Can I use it in a commercial product?
Yes. The Apache License 2.0 allows commercial use, modification and redistribution, with the licence and notice files kept.
Your agents need the whole map
40 rules, 62 hosts and verified page URLs for 40.8 million domains, in the same engine you just installed.