AgentShield
How it works Pricing Blog FAQ Contact Sign in

Best AI Agent Security Software for Mastra Agents in 2026

AgentShield Security Team·Sep 30, 2026·8 min read

Try it live

Watch AgentShield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
Interactive demo · 0 blocked in this session

Run a request

Runs the live engine on your text. Nothing is stored, no account needed.

Inspection lane

INSPECTING
⌖ untrusted input

Policy trace

High-risk action held for approval

Audit trail

For a Mastra agent that only reads and answers, the best security software is Mastra itself configured properly: requireApproval on anything that writes, PromptInjectionDetector and PIIDetector set to errorStrategy strict, and pinned packages with install scripts disabled. You need a separate product once agents write to Stripe, HubSpot, email or your own APIs, once you run durable agents that cannot use per-call approval rules, or once an auditor asks who allowed each action.

That is an unusual answer from a vendor. It is also the accurate one, because Mastra gives you better primitives than most TypeScript frameworks. The question is whether your agents have outgrown what a framework can decide on its own.

Why Mastra teams are buying security this quarter

Three things happened in 2026 that moved Mastra security from a backlog item to a budget line.

On June 17, a hijacked maintainer account was used to publish poisoned versions of more than 140 mastra and @mastra npm packages. Each one pulled in easy-day-js, a typosquat of dayjs whose postinstall hook installed an infostealer, and Microsoft attributed the operation to the North Korean group Sapphire Sleet. Any laptop or CI runner that installed during that window may have handed over the model keys and tool credentials it held.

In September, Mastra shipped releases that change how tools run. Release 1.69.0 added ClassifierProcessor, which fails closed by default, and ten new tool providers in @mastra/connect including Stripe, HubSpot, GitHub and Google Mail. Release 1.71.0 turned on eager tool execution, so tool calls start as soon as their arguments are complete instead of waiting for the model to finish. Tools that need approval still wait. Tools that do not now fire earlier than before.

And on September 22, version 2.0 of the Mastra Enterprise Edition License took effect for everything in the repository's ee directories, including the enterprise auth module, stating that source availability "does not permit Production Use" without a written agreement and license key. We cover each of these in detail on our Mastra AI security page.

What Mastra already gives you before you buy anything

Built-in controlWhat it doesWhere it stops
requireApproval and requireToolApprovalPause a tool call until you approve or decline itOff by default. Per-call policy functions work only on regular agents, not durable or stored ones
suspend() and resumeLet a tool pause for human input mid-runNeeds persistent storage or runs do not survive a restart
PromptInjectionDetector, PIIDetector, ModerationProcessorLLM-backed checks on inputs and outputsDefault errorStrategy warn, so a failed check lets content through
ClassifierProcessorTyped policy gate that fails closedJudges content, not whether an action is authorized
TokenCostControlBlocks or warns on estimated spendApproximate, and fast agents can briefly exceed the limit

If your agent has no write tools, that table may be all you need. Set the error strategies to strict and move on.

Six security options for Mastra agents compared

OptionCostBest atGap for Mastra agents
1. Mastra processors and approval, configured strictlyIncludedRead-only agents, single teamNo per-argument rules on durable agents, credentials stay in the agent process
2. Dependency hygiene in CI (lockfiles, pinning, scripts disabled, scanning)Low or included in existing toolingPreventing a repeat of June 17Says nothing about what a running agent may do
3. Mastra Teams or Enterprise platformTeams 250 dollars a month, Enterprise custom (Mastra pricing page, checked Sep 30, 2026)SSO, RBAC and audit logs for people operating agentsControls who runs and views agents, not whether a tool call should happen
4. Open-source policy engine you host (OPA, Cedar)Free license, your engineering timeTeams with platform engineers and a policy cultureYou build the integration, the approval flow and the audit store
5. LLM gateway on the model pathVariesKey management, spend caps, model failover, prompt filteringSees prompts and completions, not the tool call to Stripe or HubSpot
6. Runtime agent security layer on the tool path (AgentShield)PaidPer-tool policy, approval by a named person, decision records, several frameworks at onceOverkill for a single read-only agent

Options 1 and 2 cost nothing extra and every Mastra team should do both, whatever else it buys. Option 3 is worth it if you already run on Mastra's platform and need SSO or audit logs for your own staff. The real decision is between building on option 4 and buying option 6.

When Mastra alone is enough

Stay with the framework if all of these are true: the agent reads data but does not write, send or pay; it serves one team that already trusts each other; its inputs come from your own users rather than from email, web pages or uploaded files; and no auditor will ask you to prove which actions were allowed. A documentation assistant or an internal analytics helper usually fits. Set PromptInjectionDetector to strict, keep your lockfile pinned and spend the money elsewhere.

When you need a runtime layer on top of Mastra

The picture changes when a Mastra agent can act. The pattern we see most often is a support or operations agent wired through @mastra/connect to Stripe for refunds, HubSpot for account changes and Gmail for follow-ups. Four things break there.

First, durable agents. Teams move to durable agents so runs survive redeploys, and at that point requireToolApproval accepts only a boolean. Either every call pauses, which trains reviewers to click approve, or none do. A rule like "hold refunds over 200 dollars" has to live somewhere else. Our AI agent permissions management is where that rule sits, per tool and per argument, regardless of how the agent was built.

Second, credentials. June 17 showed that the machine building the agent is a target. If the Stripe secret key lives in the agent's environment, a stolen environment is a stolen refund capability. A gateway that holds the real credential and gives the agent a scoped token limits what a compromise yields.

Third, outside content. Support agents read email and tickets written by strangers. PromptInjectionDetector helps, but on its default setting a timeout in its model lets the message through, and even at strict it judges text rather than the action that text is trying to trigger.

Fourth, proof. When finance asks why a refund went out, a trace shows what happened. It does not show that a policy allowed it and who approved it. A tamper-evident audit trail of decisions answers that question directly.

How to evaluate any Mastra security vendor, including us

  • Does it see tool calls, or only prompts? Most AI security products sit on the model path. For Mastra agents with write tools, the risk is on the tool path.
  • Does its policy work for durable and stored agents? If the vendor's integration relies on Mastra's per-call approval function, it inherits the same limitation.
  • Who approves? The approval should come from a named person in your organization, bound to the exact arguments shown, not from the client that made the request.
  • Does it cover your other frameworks? Many Mastra shops also run Python agents. One policy for both beats two partial ones. See our Pydantic AI security and LangChain security pages for how that looks.
  • Can it hold the credentials? After June 17, a product that leaves every write key inside the agent process is solving half the problem.

If the purchase has to pass a formal vendor review, running it through your usual procurement workflow keeps the security questionnaire, the DPA and the approval history in one place, which your auditor will ask for later anyway.

Our recommendation

Every Mastra team should pin packages, disable install scripts in CI, rotate anything exposed in June and set its guardrail processors to strict. That costs nothing. If your agents only read, stop there. If they write to payment, CRM or email systems, run durable agents, or answer to an auditor, put a runtime policy layer on the tool path so the same rule applies to every agent and every framework. That is what human approval for AI agents and the rest of AgentShield are built for, and you can connect your first Mastra MCP server in an afternoon.

Questions Mastra teams ask before buying

What is the best AI agent security software for Mastra?

For read-only agents, Mastra itself with strict guardrail processors and pinned packages is enough. For agents that write to payment, CRM or email systems, add a runtime layer on the tool path, such as AgentShield, that enforces per-tool policy, routes high-value calls to a named approver and records every decision.

Does Mastra have built-in security?

Yes. Mastra provides tool approval, suspend and resume, and processors for prompt injection, PII, moderation, cost and classifier policies. Most are opt-in, and model-backed processors other than ClassifierProcessor default to warn on failure, so a secure setup changes those defaults deliberately.

Do I need to rotate keys after the Mastra npm attack?

If any machine installed affected mastra or @mastra package versions around June 17, 2026, yes. Microsoft recommends checking lockfiles for easy-day-js, pinning known-good versions, installing with scripts disabled and rotating any credentials, tokens or API keys that could have been exposed.

See the firewall block an attack live.

Drive the Threat Console and watch a real prompt injection get stopped, then put AgentShield in front of your own agents.

Open the console