Patronus Ark, a local security scanner for AI agents

Reddit r/AI_Agents Tools

Summary

Patronus Ark is a new Rust and Python library for locally scanning AI agent text and tool activity, covering prompt injection, PII, data leakage, and tool-related risks without sending data to external APIs.

Hi, we have released a Rust and Python library for scanning the text and tool activity of AI agents. Patronus Ark can inspect user prompts, retrieved documents, tool descriptions, proposed tool calls and the results returned by tools. The scanners cover prompt injection, PII, data leakage, sensitive documents, tool classes, tool actions and security related tool properties. For example, an application can scan a document before adding it to an agent context, scan a tool call before execution and scan the returned tool output before giving it back to the model. Ark only produces classifications. It does not execute or block tools. The application decides whether a result should be allowed, rejected or sent for approval. The core is written in Rust and uses local ONNX models where native detectors are not sufficient. Python bindings are available through PyO3. After downloading the model files, scans run without sending the inspected content to an external API. I am one of the developers and work for the company maintaining the project. The repository is GPL-3.0-only, with a separate commercial license for proprietary distribution.
Original Article

Similar Articles

Arcjet

Product Hunt

Arcjet is a runtime security platform designed to protect AI agents by detecting threats like prompt injection, authorizing tool calls, redacting sensitive data, and blocking bots and abuse in real-time.

Introducing Aardvark: OpenAI’s agentic security researcher

OpenAI Blog

OpenAI announces Aardvark, an AI-powered agentic security researcher built on GPT-5 that automatically identifies, validates, and patches software vulnerabilities in codebases. The tool integrates with GitHub and development workflows to help security teams discover and fix vulnerabilities at scale.

Show HN: We post-trained a model that pen tests instead of refusing

Hacker News Top

ArgusRed is a CLI tool that uses a post-trained AI model to perform security scanning and penetration testing on codebases, outputting detailed markdown reports. It offers two modes: security scan (read-only) and pen test (active exploits) with optional exploit verification.