Runtime security for AI agents. Catches what your AI misses.
14-day full Pro trial, no card required.
pip install -U insa-itsgives you the complete feature set for 14 days: all 30 detectors, every Phase 3 reliability gate, Session Vault, RABE export, Session-SAE, decipher engine. After the trial, pick a tier — Starter $10/mo or Pro $49/mo. Detection always keeps running; a paid key unlocks active intervention.
InsAIts monitors AI-to-AI communication in real-time. It watches every tool call, every response, and every agent-to-agent message for security anomalies — credential leaks, hallucination chains, prompt injection attempts, unauthorized writes, rogue subagent behavior, and 25+ more anomaly types. When it catches something critical, it intervenes immediately by injecting corrective instructions into the agent's context, before the damage reaches your codebase.
It runs as a Claude Code hook. You install it, and it works silently in the background. No configuration needed.
These are real numbers from real sessions, not benchmarks:
| Metric | Value | Context |
|---|---|---|
| PyPI downloads | 20,120+ | Total installs of insa-its |
| SDK version | 4.9.4 | Latest release on PyPI — 14-day full Pro trial on install |
| MCP Registry listing | active | io.github.Nomadu27/insaits published in the official MCP Registry |
| Smithery manifest | active | smithery.yaml declares the MCP server for one-click install |
| Anomaly detectors | 30 | Full TRS-weighted detector suite (see full list) |
| OWASP coverage | MCP Top 10 + Agentic AI Top 10 | ASI01–ASI10, with CVE references |
| Tests passing | 2,267 | API (872) + SDK (1395), full detector + integration + E2E |
| Longest continuous session | 9h 16min | Single session, minimal interruptions |
| Anomalies caught and corrected | 682+ | Across multi-terminal sessions |
| Trial length | 14 days | Full feature access, no card required |
| Data sent to cloud | 0 bytes | Everything runs locally |
InsAIts is the security core of the AgentShield runtime, a fork of Everything Claude Code ecosystem,. AgentShield is our feat/insaits-security-hook branch of everything-claude-code — same codebase, rebranded downstream. If you use AgentShield, you're running InsAIts.
14-day full Pro trial on every install — no card, no key, no env var.
pip install -U insa-itsand the full Pro feature set is active for 14 days. After that, pick a tier below; detection keeps running in passive mode even without a key.
| Tier | Monthly | Lifetime | What unlocks |
|---|---|---|---|
| Trial | free | 14 days | Full feature access, no card |
| Starter | $10 | $99 | All 30 detectors, all Phase 3 reliability gates, Session Vault, full dashboard, work-checkpoint continuity |
| Pro | $49 | $299 | Starter + L3 subagent anchors, Session-SAE behavioral anomaly detection, inter-session dialog, RABE export, Decipher engine, cloud embeddings, priority support |
| Enterprise | from $200 | custom | SOC2-ready audit export, multi-seat, white-label dashboard, dedicated support |
Buy a tier, or support development directly — every contribution funds the next detector batch and the open-source roadmap:
Enterprise: info@yuyai.pro.
- 💳 Payments live — 14-day full Pro trial on install. Every
pip installstarts a 14-day trial with the complete feature set: all 30 detectors, every Phase 3 reliability gate, Session Vault, RABE export, Session-SAE, decipher engine. After the trial, Starter ($10/mo) or Pro ($49/mo) unlock active intervention; detection keeps running in passive mode regardless. - Tier mapping + Stripe/Gumroad checkout hardened end-to-end so the right plan unlocks the right features.
- Full SDK suite green on the current build.
- PyPI wheel completeness — fix
setup.pyso non-Python data files (manifests, schemas, anchor assets) ship inside the wheel instead of being skipped by setuptools. Resolves a class of "works locally, fails onpip install" reports. - Collector decomposition complete (Waves B1–B9) —
insaits_collector.pyis now a coordinator over nine focused modules:collector/_config.py,_state.py,_security.py,_sdk_loaders.py,_evidence.py,_events.py,_detectors.py,_hook_config.py,_audit_writer.py. The monolith dropped by several thousand lines; surface and behavior are unchanged. - Dashboard decomposition (Waves A1–A4) — HTML, demo data, message history, and session routing extracted into the
dashboard/package. Cold start is faster and a long session keeps a lower memory footprint. - Detector FP fix — unverified_source_claim on file writes — file bodies passed to
Write/Edit/MultiEditno longer trigger the "unverified source claim" detector, which was firing on code that simply contained quoted strings about authors or sources. False-positive rate dropped sharply for normal editing workflows. - Test-suite hygiene — autouse audit-sidecar redirect closes a pollution-invariant leak that was masking real failures across suites; sgtest-/m7- audit isolation tightened; SAE perf cap relaxed for slow CI.
- MCP Registry + Smithery listing —
io.github.Nomadu27/insaitsis published in the official MCP Registry, andsmithery.yamldeclares the server for one-click install via Smithery. Discovery now happens through the standard MCP toolchains, not just PyPI. - AGENT_MANIFEST.json — machine-readable manifest covering version, status, and feature surface. Tooling and agent platforms can read the manifest without scraping a release page.
- Daemon lifecycle hardening — work-checkpoint continuity, Guardian Session Vault save+resume, and the Phase 3 reliability gates (premature-completion, unverified-assertion, compliance-bypass) all promoted from preview to default-on. Tested under stress + restart cycles.
- OpenAPI collector spec —
docs/openapi-collector.yamldescribes every collector endpoint (hooks, dialog, evidence, snapshots, guardian, license). Generated from the same source the daemon serves, so the contract cannot drift.
- Audit log redaction — secrets in tool calls (API keys, AWS creds, Bearer tokens, password K=V) are scrubbed on the persist path so audit history is safe to share. Detectors still see raw text in memory.
- Modern OpenAI key formats —
sk-proj-,sk-svcacct-,sk-user-,sk-admin-are now caught by redaction. The previous pattern stopped at the first hyphen and missed them. - Daemon hook architecture — hooks moved from in-process runners to a lightweight HTTP shim that responds in <50 ms. The daemon owns all state.
- Per-install daemon authentication — each install writes a unique token. Hook calls authenticate against it, preventing rogue connections.
- Windows non-ASCII fix — hook shim now decodes stdin as UTF-8, so Cyrillic / CJK / emoji / accented Latin payloads are no longer mangled.
- Programmer bugs surface — hook shim used to swallow every error as "daemon error". Now
RuntimeError/AssertionError/ImportErrorpropagate so real bugs are visible to the operator instead of silently failing open. - Legacy runner tripwire — the old in-process runner refuses to start unless explicitly opted in via
INSAITS_ALLOW_LEGACY_RUNNER=1. Prevents silent regression from a restored backup that bypasses audit + auth. - OWASP canonical names — every detector code carries a canonical OWASP name field. A parametrised guard test pins the mapping so future drift fails CI.
- Subagent observability (L2 Layer) — full visibility into subagent tool calls with parent-agent linkage, scope-drift guard, and rogue-intent detection.
- Work-checkpoint continuity — Guardian Session Vault captures task progress every 50 tool calls. Recover from context compression cleanly.
- Lean observability — token-optimization pass saves ~1,200–1,800 tokens per clean session.
- Session-SAE (Pro/Enterprise) — autoencoder-based behavioral anomaly detector catches session-pattern drift that rule-based detectors miss.
- False-positive fixes (FP1–FP5) — implementer-verb whitelist, adaptive subagent TTL, JSON-crash fix on set/frozenset encoding,
cwd-audit every entry. - Truth-first dashboard — feed semantics match what actually fires.
Full technical notes live on the API repo releases page.
Open your browser at http://localhost:5001 after starting insaits-dashboard. You get:
- Threat Readiness Score — TRS v2 with cooldown, variety gate, and time-weighted signals
- Anomaly Feed — live stream of detected issues with severity levels and details
- Agent Intelligence Scores — each agent scored independently (trust level, stability, anomaly rate)
- Blast Radius — severity-weighted impact measurement across your session
- Intervention Log — shows when InsAIts corrected an agent and what happened next
- Circuit Breaker — manually pause/resume AI execution with one-click toggle
- OWASP Panel — full MCP Top 10 + Agentic AI Top 10 compliance view with CVE references
- Agent Communication Map — visual graph of agent-to-agent message flows
- Subagent Drill-Down — per-subagent tool-call traces with rogue-intent flags
- RABE Analysis — Risk-Adjusted Behavioral Entropy tracking per session
- Session Vault — full session state, snapshots, work-journal checkpoints
- Token Budget — live injection cost tracking (MEASURED vs ESTIMATED vs OVERHEAD)
InsAIts catches issues as they happen, not after. Full detector list (TRS-weighted):
Security-critical (OWASP MCP Top 10):
- Credential exposure, prompt injection, tool poisoning, data exfiltration
- Shadow server, unauthorized access, unauthorized write, exfiltration pattern
- Entropy covert channel
Behavioral / integrity:
- Rogue agent, hallucination chain, memory poisoning, information flow
- Phantom citation, chain tampering, semantic drift, agent probing pattern
- Signature match (known-bad patterns)
Communication quality:
- Shorthand emergence, context collapse, truncated output
- Uncertainty propagation, governance gap
Advanced / adaptive:
- Behavioral fingerprint, tool call frequency anomaly, tool description divergence
Session health predictors:
- Context exhaustion predicted, edit spiral predicted, scope drift predicted
Pro/Enterprise tier:
- Session-SAE (session pattern anomaly) — autoencoder behavioral detector
InsAIts does not just alert — it acts. But only rogue-agent behavior can block:
_BLOCKING_SEVERITIES = {"CRITICAL"}— only CRITICAL severity ever gates the next tool calltool_type_mismatch,compliance_bypass_attempt,checklist_without_execution→ HIGH warnings, non-blocking- Rogue-intent detection (subagent scope drift, agent probing) → HIGH/MEDIUM, alert-only
- Infrastructure DENY only on retry-storm or circuit-breaker — not on agent behavior
- Layer-respect: L1/L2/L3 anchor injections honor per-layer enable toggles, anomaly-delta gates, and shorthand gates
Toggle stealth on/off from the dashboard. In stealth mode, InsAIts monitors without the AI knowing. Useful for security auditing where you want to observe natural agent behavior.
Run multiple AI agents in different terminals? InsAIts lets them communicate:
- Send messages between terminals from the dashboard
- Coordinate work across agents (file locks, task assignment)
- See the full dialog thread in the dashboard
For long sessions (hours), InsAIts automatically:
- Saves work snapshots every 50 tool calls (v4.8.0.2)
- Detects context compression (when Claude forgets earlier work)
- Injects a resume anchor with your progress so the AI picks up where it left off
- Captures task-progress checkpoints in the Session Vault
- Emergency-saves on crash so nothing is lost
Each agent gets a behavioral profile. InsAIts detects when an agent starts behaving differently from its baseline — which can indicate a compromised tool, prompt injection, or model degradation.
Drop-in integrations for popular agent frameworks. Monitor LangChain chains, CrewAI crews, and LangGraph workflows with the same anomaly detection and intervention engine.
After each session, InsAIts can learn from what it saw. It identifies recurring patterns specific to your project, reducing false positives and catching real issues faster. In v4.8, patterns feed an SQLite intelligence store shared across sessions.
pip install insa-its[full]Add this to your .claude/settings.json:
{
"hooks": {
"PreToolUse": [
{
"type": "command",
"command": "python -c \"from insa_its.hooks import run_hook; run_hook()\"",
"timeout": 10000
}
]
}
}Then add this to your project's CLAUDE.md so Claude reads the Guardian work log:
## PHASE_GUARDIAN — Session Continuity
When you see a `[InsAIts Resume Anchor]` in a tool result, trust it.
It is your work journal from the Guardian. Use it to pick up where
you left off without re-reading everything.from insa_its import insAItsMonitor
monitor = insAItsMonitor()
result = monitor.send_message(
text="Here is the API key: sk-abc123secret",
sender_id="agent1",
llm_id="gpt-4o"
)
for anomaly in result["anomalies"]:
print(f"[{anomaly.severity}] {anomaly.type}: {anomaly.details}")See example.py for the complete working example.
Click the image above to watch the dashboard in action.
- No cloud calls. Zero. Every byte of processing happens on your machine.
- No telemetry. We do not track usage, sessions, errors, or anything else.
- No data leaves your machine. Your code, your prompts, your AI responses — they stay on your disk. Period.
- No API keys required. Install and use. That is the entire setup.
InsAIts was built during live sessions with Claude Code. The integration was contributed to the everything-claude-code repository as PR #370, confirmed by Affaan (Anthropic).
- PyPI Package —
pip install insa-its - Website
- YouTube Playlist
- YouTube Channel
InsAIts is developed by Steddy Nova SRL / YuyAI. The source code is in a private repository. The package is fully functional via PyPI.
Contact: info@yuyai.pro
Licensed under Apache 2.0 (open-core SDK; the collector, dashboard, and paid-tier detectors are proprietary and licensed separately).
© 2026 Bogdan Cristian / Steddy Nova SRL. All Rights Reserved.


