Back to the registry
Agent passport

CyberArk Agent Guard

CyberArk · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownContainer
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Agent Guard delivers secure secret retrieval and observability for AI agent communications by reducing the risks of unmonitored access and hardcoded secrets. Designed for environments using STDIO communication, it helps keep secrets ephemeral, centrally managed, and out of code.

By auditing all interactions and integrating with AWS Secrets Manager or CyberArk Secrets Manager (previously CyberArk Conjur), Agent Guard provides dynamic, just-in-time secret injection, empowering organizations to meet high standards of compliance, traceability, and operational security without compromising performance or flexibility.

Show the rest of the publisher’s description (12 more lines)

Usage instructions:

  • github.com/cyberark/agent-guard/blob/main/docs/agent-guard-containerized.md

Key capabilities and differentiators:

  • Auditing and monitoring: Interactions between the AI agent and MCP servers are logged, providing complete traceability and compliance with enterprise security standards.
  • STDIO-based deployment support: Ideal for local or containerized environments, the proxy supports STDIO communication while isolating the MCP server from direct access to sensitive data on the host.
  • Dynamic secret injection: Secrets are ephemeral, so they are not stored in code or local files. Instead, they are dynamically retrieved from your secrets manager (AWS Secrets Manager or CyberArk Secrets Manager), injected into the MCP server session, and disposed of after use.
  • Lightweight and flexible: Easy to deploy and integrate into existing AI workflows without introducing significant overhead.

Integration with AWS:

  • Agent Guard is configurable with the Amazon Q Developer agent to trace and audit interactions with MCP servers using Agent Guard MCP proxy capability. It can be used for securely retrieving secrets required by the AWS Q Developer agent and its tools. Those secrets can be retrieved from AWS Secrets Manager or CyberArk Secrets Manager.
  • Optional integration with AWS CloudWatch: Centralized logging and monitoring for enhanced observability.
  • IAM Role support: Allows only authorized agents to access specific secrets or perform actions.

Please note: this offering is offered free-of-charge and is therefore subject to section 1.4 of the CyberArk SaaS Terms of Use.

Highlights

Highlighted by the publisher on AWS Marketplace.

Auditing and monitoring: Interactions between the AI agent and MCP servers are logged, providing complete traceability and compliance with enterprise security standards.

Dynamic secret injection: Secrets are ephemeral, so they are not stored in code or local files. Instead, they are dynamically retrieved from your secrets manager (AWS Secrets Manager or CyberArk Secrets Manager), injected into the MCP server session, and disposed of after use.

STDIO-based deployment support: Ideal for local or containerized environments, the proxy supports STDIO communication while isolating the MCP server from direct access to sensitive data on the host.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Refund terms

As stated by the publisher on AWS Marketplace.

CyberArk Agent Guard is a free offering.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
CustomEulaCustomEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Container
No product warranty or support is provided with Agent Guard. Instead, visit our repository at github.com/cyberark/agent-guard and join our community to connect with developers, ask questions, and share DevOps security best practices. Please note: this offering is free of charge and is, therefore, subject to section 1.4 of the CyberArk SaaS Terms of Use.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.