Show HN: ModelFuzz – Open-source runtime guardrails for AI agents ModelFuzz, an open-source runtime guardrails tool for AI agents, detects and blocks indirect prompt injection attacks that can hijack LLM agents into executing arbitrary commands, exfiltrating secrets, or leaking data. The tool includes a red-team scanner to expose vulnerabilities and a decorator to shield tools by checking arguments against policies before function execution. Prompt injection turns your agent's own tools against you. A single poisoned document, email, or web page can hijack an LLM through indirect prompt injection, compromising LLM agent security at the source. The model thinks it's helping. It isn't. - shell.run — arbitrary command execution on your infrastructure. - http.post — silent exfiltration of secrets to an attacker's server. - send email — API keys and customer data leaked to attacker@evil.com. - Prompt-level filters can't guarantee safety. Model behavior is non-deterministic . Find the holes. Then seal them. ModelFuzz ships with both halves of the security loop — a red-team scanner to expose vulnerable agents, and a decorator to shield them. The Scanner Red-team any OpenAI-compatible endpoint with deceptive prompt-injection payloads. See exactly which attacks trick your agent into calling a tool. The Shield Wrap any tool with one decorator. Every argument is checked against your policies before the function runs — a violation raises before damage is done. An attack, stopped in real time. A prompt-injected agent tries to exfiltrate an API key. ModelFuzz catches it at the execution layer. Want a hosted dashboard for your team? Centralized policies, audit logs, and continuous agent scanning. Join the waitlist for early access.