ShieldCortex
Stop your AI agents leaking, hallucinating, or getting hijacked.
ShieldCortex v5.0.6 sits on the door of your agent's native memory: it scans writes, gates tools, and lets you inspect what was stored. It does not replace OpenClaw, Hermes, or Claude memory. Requires Node 22.14+ or Node 24. Action Guard stays off by default.
Free open source · MIT licensed · npm install shieldcortex
Features
What it does.
Inspectable Memory
See what the agent stored, where it came from, and what it would recall next. Capture, Recall, Review, and graph views turn memory into an operator-controlled workflow.
Inspectable Recall
Search and review what was stored. Automatic inject into every conversation is off. Native OpenClaw / Hermes / Claude memory stays the brain; ShieldCortex is the door.
Memory Poisoning Defence
Every memory write passes through a 6-layer defence pipeline covering prompt injection, encoding tricks, paraphrased attacks, format anomalies, behavioural anomalies, and credential leakage before it lands.
Iron Dome Behavioural Protection
Agent-aware security that controls what your AI can do, not just what it remembers. Injection scanning, action gates, PII guard, and emergency kill switch.
Environment Firewall
Third defence layer — protects what the agent sees. shieldcortex env scan <url> scores provenance, detects hidden instructions (display:none, visibility:hidden, bidi overrides, same-colour text), and runs injection scanning on visible and hidden surfaces separately. A prompt-injection hit inside hidden content marks the page hostile regardless of the domain.
MCP-Native Workflows
Works as a standalone MCP memory server or integrates with OpenClaw, Claude Code, VS Code, Cursor, and Codex through the shared MCP config.
X-Ray Scanner
Deep file and dependency analysis for prompt injection, steganographic payloads, obfuscated code, credential leaks, risky packages, and CI gatekeeping before bad code lands.
Operator Review Workflows
Suppress, archive, pin, canonicalize, merge, and replay. Teams can investigate incidents, review suspicious memory, and keep future recall under control instead of trusting a black box.
Open Source, MIT Licensed
Free and open source under the MIT licence. The full defence pipeline, custom patterns and policies, audit export, X-Ray scanning, and the Cortex memory system all run locally at no cost.
Structured Memory Types
v4 organises memory into four typed categories — user preferences, feedback from corrections, project context, and reference knowledge — so recall is always scoped to the right kind of information.
Staleness Scoring & Decay
Memories age. v4 applies time-based decay scoring so stale entries sink in relevance, with operator warnings when recalled memories are old enough to be unreliable.
LLM-Powered Reranking
Hybrid recall combines vector similarity with an LLM reranking pass, surfacing the most contextually precise memories instead of just the nearest embeddings.
Dream Mode Consolidation
Run shieldcortex consolidate to trigger background memory consolidation — like sleep for your AI. Dream mode merges duplicates, resolves contradictions, and strengthens important memories offline.
Memory Scopes
Private and team scopes let multi-agent fleets share project context while keeping per-agent preferences isolated. Control exactly what crosses the boundary.
Cloud Replica Sync
Opt-in local-to-cloud replication for memories and graph data, with queue diagnostics, per-project controls, and shared visibility for teams running across multiple devices.
Positive Feedback Capture
v4 doesn't just learn from mistakes. It captures confirmations, successes, and explicit praise so agents reinforce what works — not only what went wrong.
Smart Save Filtering
Before a memory is written, v4 checks whether it's derivable from existing entries or redundant. Duplicate and low-value information is blocked at the gate, keeping memory lean.
How it works
3 simple steps.
Capture
Install ShieldCortex on the host you already run. Native memory stays the brain. Writes that go through ShieldCortex get provenance, trust scoring, and a defence scan before they stick.
Inspect
Use Capture, Recall, and Review to see what the agent stored, what it would retrieve, and what should be suppressed, merged, archived, or marked canonical.
Protect
Every memory write is scanned through all six layers. Iron Dome gates risky behaviour. Cloud teams then use Device Doctor, Verify, Replay, and Review to investigate incidents and remediate them.
Iron Dome — behavioural security
The memory firewall protects what your agent stores. Iron Dome protects what it does. Six defensive layers — instruction gateway, injection scanner, action gating, PII protection, kill switch, and audit trail — with four ready-made profiles for personal, school, enterprise, and paranoid deployments. Free and MIT licensed, included with ShieldCortex.
See It In Action
Watch ShieldCortex block a prompt injection and privilege escalation in real time.
Also on X/Twitter
Pricing
Simple, transparent pricing.
Free
£0
Everything runs locally — free, open source, MIT licensed
- ✓Full 6-layer defence pipeline
- ✓Iron Dome with custom policies
- ✓Custom injection patterns + firewall rules
- ✓Credential leak detection (25+ patterns)
- ✓Audit export (JSON/CSV)
- ✓X-Ray scanner + CI gate
- ✓Cortex memory system + knowledge graph
- ✓Operator recall / search (FTS5) — automatic inject off
- ✓Structured memory types, staleness scoring & decay
- ✓Local dashboard
- ✓Agent hooks (OpenClaw, Claude Code, Cursor)
- ✓Free cloud tier (500 scans/month sync)
Enterprise
Custom
For teams and fleets — contact us
- ✓Everything in Free
- ✓Fleet deployment and management
- ✓Memory sync at scale
- ✓SSO + volume licensing
- ✓Self-hosted deployment
- ✓SIEM integration + compliance exports
- ✓Dedicated support + SLA
Frequently Asked Questions
Does ShieldCortex require a cloud account?+
How does the 6-layer defence pipeline work?+
What is ShieldCortex best at?+
What is Iron Dome?+
What is the Environment Firewall?+
Is there a done-for-you option?+
Which AI tools does ShieldCortex integrate with?+
How do Cloud API key scopes work?+
What does Incident Replay actually show?+
What's new in v5.0.6?+
Secure Your AI Agent Memory with v5.0.6
Scan native memory writes, gate tools, inspect what was stored. Open source, MIT licensed. Get started in under a minute.