You didn’t write this agent.
Screen what it sends.
To use an open-source AI agent or MCP server you did not write, route its LLM traffic and model downloads through a security proxy so you can see and screen what it sends. AiDren screens the agent's prompts and responses, scans any model files it downloads, and its worker-agent package flags unexpected outbound connections.
How to secure a third-party agent or MCP server
Wrap it, don’t trust it.
You do not need to read the agent’s source. Route what leaves it through AiDren and you get a decision log of what it actually did with your keys and data.
-
1
Repoint its LLM calls
Set the agent’s base URL and key to an AiDren proxy key. Its prompts and responses now get injection and data-leak screening.
-
2
Route its model downloads
Send its Hugging Face and GitHub pulls through AiDren too, so any model file it fetches is scanned before it lands.
-
3
Add the egress watcher
Drop in the worker-agent package and its outbound connections get flagged when they go somewhere unexpected.
One decision log for code you didn’t audit
The agent stays a black box; what it sends does not.
- Prompt + response screening on everything the agent sends and receives.
- Model-file scanning on anything it downloads — pickle, safetensors, GGUF, ONNX, joblib, Keras.
- Egress flags when it connects somewhere off your allowlist.
- Custom policy to constrain what it is allowed to say or do.
- A full decision log of what it actually did with your keys and data.
Related: Malicious model-file scanning · Agent egress monitoring · How AiDren compares →
A decision log of everything the agent did.
A real screen from a live AiDren account.
What is prompt injection?
Prompt injection is when someone hides instructions inside content your AI reads — a webpage, an email, a file — hoping your model follows them instead of you. AiDren screens every request before it reaches your model, catching injected instructions before they can hijack your agent.
Where do you scan model files from, and which formats?
Hugging Face Hub and GitHub: release assets and raw files. Route the download through AiDren and it's scanned for malicious code before it reaches disk, across pickle (including ones wrapped inside a torch.save ZIP), safetensors, GGUF, ONNX, joblib, and Keras. Non-model files pass straight through.
Do you scan the model's responses too, not just the prompt?
Yes. Output scanning checks every response for system-prompt leaks and common data-leak patterns, including emails, card numbers, IBANs, phone numbers, API keys, and private keys, before it reaches your app. You choose per key whether a hit gets redacted or the whole response blocked, and whether prompts get the same check.
What happens after the trial?
Your 14-day trial needs no card up front and covers 25,000 checked requests. When it ends, upgrade to keep your proxy running — if you don't, AiDren pauses your traffic rather than silently letting it through unprotected.
Are MCP servers safe to install?
Not by default. A third-party MCP server can return tool output containing hidden instructions, ask for more access than it needs, or change behaviour after you approved it. Review the source, grant least privilege, and screen what the agent sends and receives.
Can AiDren make an untrusted agent safe?
No. It gives you screening and a decision log for the traffic that passes through it, plus flags for unexpected connections when the worker-agent is installed. It does not sandbox the agent's code, so run untrusted agents in a container or VM as well.
Put a checkpoint around
the agent you didn’t write.
Get the full stack free for 14 days. No card, no sales call, no SDK rewrite.
Start protecting requests