superagent_

Y Combinatorbacked by Y Combinator

Security forAI-native developers

trust what you merge, control what your agents do, and show your users it's safe. free for open source.

customers

ubicloudevry healthdotenvxfirecrawlcapchasenangomastrapaperclip

products

trust the change

checks on every pull request, before merge. vulnerabilities, supply-chain risk, who's behind the code, and whether the cla is signed — findings on the exact line, fixes as pull requests.

pr scans

vulnerability checks on every pull request.

  • inline review comments
  • github check runs
  • patches as prs

docs

contributor trust

know who is behind the code before it merges.

  • risk scores per contributor
  • supply-chain flags
  • private by default

docs

agreements

cla templates, versions, and signing workflows.

  • cla templates
  • signing bot
  • version control

docs

control it where it runs

boundaries around what your agents can see, say, and do — and a record of what they did.

guardrails

block prompt injections and unsafe tool calls at runtime.

  • prompt-injection detection
  • tool-call policy
  • automatic redaction

docs

runtime

see what your agents do and catch unsafe behavior.

  • session-level visibility
  • rules and detections
  • alerts with context

break it before it ships

self-serve red teaming against what you actually run. black-box against the public surface, gray-box with repo context. every finding ships with repro steps and the payload that worked.

how it works

you already work in your coding agent and github. so that's where superagent works too — no new workflows or tools to learn.

three steps, no new habits

01 create your account connect repos, manage keys, invite your team

02 connect to github keeps your repos secure

03 add the mcp server red-team your code and agents from your coding agent

covered from first prompt to production

changelog

customer quotes

i wish i could just let our agents run free and solve all our problems. but at what cost? superagent helps us sleep better at night.

it chained vulnerabilities together the way a real attacker builds a kill chain and found exploit paths. a week later, a threat intelligence scanner flagged the same vulnerability. by then it was already fixed.

you guys are the best.

devin foley, co-founder & cto, paperclip

[ all customer stories ]

get started

free for open source.

the whole suite, on any public repo. private repos are paid — contact us and we'll set you up.