For teams running AI agents with tool access: a free MCP server and security Check, plus a $49 Field Kit playbook. Least privilege, audit and deny-by-default tools instead of system-prompt promises.
From 20 educational AI-security sources (2026). Top risks we bake into Check & Playbook:
Also weighted: excessive agency, tool abuse, MCP supply chain, secrets, exfil, guardrails, token delegation.
Defense in depth for LLM apps, agents, MCP servers, and multi-agent workflows.
MIT-licensed local MCP server: Ed25519 agent identity, AES-256-GCM vault, signed hash-chained audit log, deny-by-default scope checks, and a kill switch. Source on GitHub.
Interactive self-assessment scored from weighted AI security themes. Works offline in your browser. Run the free Check.
Dense playbook plus deny-by-default tools, MCP allowlist, secrets, and kill-switch YAML templates.
Everything in the Field Kit, for teams that want to back the free MCP server. No Pro-only files today.
We weight Bot Lock Check and the playbook toward the themes that show up most — so you fix what matters first.
| Theme | Weight | Coverage |
|---|---|---|
| Prompt injection / jailbreak | 16/20 | |
| Logging / monitoring / audit | 16/20 | |
| Least privilege / IAM | 12/20 | |
| Excessive agency / autonomy | 11/20 | |
| Agent tool abuse | 11/20 | |
| Supply chain / MCP / plugins | 11/20 | |
| Secrets management | 10/20 | |
| Data exfiltration / privacy | 9/20 | |
| Guardrails / I/O filtering | 9/20 | |
| Token delegation / OAuth | 9/20 |
The MCP server and Check are free. Field Kit and Pro are one-time Stripe checkouts on the First Deploy account. After pay you land on the playbook.
Live Stripe checkout.
Live Stripe checkout.
Honest positioning: Bot Lock reduces agent risk when you apply layered controls. It does not guarantee zero successful injections or replace authorized red-team verification.
Score your agent setup against the weighted themes above. Runs in your browser, works offline, and gives you a shareable risk snapshot. Run the free Check.
MIT-licensed and local: Ed25519 agent identity, AES-256-GCM vault, signed hash-chained audit log, deny-by-default scope checks and a kill switch. Source on GitHub.
The full playbook plus policy YAML for deny-by-default tools, MCP allowlist, secrets and kill switch, and a 30-day adoption plan. Read the free preview.
Dense, defense-only guidance: principles, checklists, anti-patterns, and a verification playbook for systems you own. Read the contents and chapter 1 free.
Read the previewQuestions on Field Kit, Pro, or an enterprise rollout? Email Daniel Graham at AgentHive Inc.
Email DanielAgentHive Inc·About Daniel Graham·Consult·First Deploy·AI Nexus 360·Infrastructure·Flick·JobProof·IndexMe·Bot Lock
Built by Daniel Graham, founder of AgentHive Inc · 25 years in enterprise IT and telecom · Palm Coast, FL · 320-335-6186 · daniel@agenthiveinc.com