macOS App — 100% Offline

See what your AI agents
can really access

RootShield scans your MCP servers, API keys, and agent configs — then shows you the exposure graph. 100% offline. Zero data leaves your machine.

Free tier includes Secrets layer, Skill Shield, and Integrations

📊 Screenshot: Exposure Graph
Works with

The attack surface is growing

Every AI agent you install adds API keys, config files, and MCP connections to your machine. Nobody can see the full picture.

41.7%
of OpenClaw skills have security vulnerabilities
32%
of MCP servers have critical vulnerabilities
1,467
malicious payloads found in supply chain attacks

Developers run 3–5 AI agents with MCP servers, API keys, and configs scattered across their machine. A single misconfigured agent can expose secrets to every service it connects to. You need a way to see the exposure — before something goes wrong.

What RootShield shows you

One tool to map every connection between your agents, secrets, and external services.

🕸

Visual Exposure Graph

See every connection between your agents, secrets, and external services in an interactive force-directed graph.

🛡

7 Risk Layers

Secrets, Permissions, Supply Chain, Egress, Schedule, Prompt Injection, and Cross-Agent — each a distinct view of your exposure.

Skill Shield

Analyze any MCP server or skill before installing. See its capabilities, signals, and blast radius on your workspace.

🔍

Context Shield

Make your AI agents security-aware with automatic CLAUDE.md instruction file generation and monitoring.

🔔

Continuous Monitoring

Real-time alerts when agent configs change, with full source attribution so you know what happened and why.

📈

Workspace Drift

See exactly what changed between inspections. SHA-256 baselines for every skill and config file on your machine.

Three steps to full visibility

No agents, no SDKs, no sign-up. Just a native macOS app that reads your local configs.

1

Connect

Grant read-only access to your agent config folders. RootShield never writes to your files.

2

Inspect

One click scans everything — agents, MCP servers, secrets, and configs. Takes under 3 seconds.

3

See

Your exposure graph, posture score, and actionable findings — all in one view. No data ever leaves your machine.

Start free. Upgrade when you need more.

Free tier gives you real security insights. Pro unlocks the full picture.

Free
For individual developers
$0
Free forever
  • Secrets exposure layer
  • Findings summaries
  • Skill Shield (3 analyses/mo)
  • Integrations tab
  • Posture score & grade
Download Free
Team
For security-conscious organizations
$39 / seat / mo
Volume discounts available
  • Everything in Pro
  • Team posture dashboard
  • Shared compliance reports
  • Priority support
  • Feature tuning requests
Contact Us
Founding Member Lifetime Deal: $199 One-time payment. All Pro features forever. First 300 buyers only — direct download.

Trusted by security-conscious developers

Early adopters are already using RootShield to secure their AI workflows.

★★★★★

"I had no idea my Cursor setup was exposing 4 API keys to an MCP server I barely use. RootShield showed me in seconds."

AK
Alex K.
Senior Developer
★★★★★

"The exposure graph is the killer feature. It makes the invisible visible. This should ship with every AI agent."

SR
Sarah R.
Security Engineer
★★★★★

"Skill Shield caught a suspicious MCP server before I installed it. Saved me from a supply chain headache."

JM
James M.
DevOps Lead

Frequently asked questions

No. RootShield is 100% offline. It reads your local agent config files and renders everything on your machine. Zero network calls, zero telemetry, zero data collection. Your secrets stay on your device.

RootShield supports Claude Code, Cursor, Windsurf, Cline, OpenClaw, Gemini CLI, Ollama, LM Studio, Aider, Codex, Copilot, and any MCP server. New agents are added regularly — the scanner architecture is modular and extensible.

No. RootShield has a one-click Inspect button that scans everything automatically. The exposure graph and posture score make it easy to understand your security posture at a glance, even without a security background.

Free gives you the Secrets layer, findings summaries, 3 Skill Shield analyses per month, and the Integrations tab. Pro unlocks all 7 risk layers, the composite view, remediation guidance, Workspace Drift, Context Shield, monitoring details, exports, and unlimited Skill Shield.

Yes. The Team tier ($39/seat/month) includes everything in Pro plus a team posture dashboard, shared compliance reports, priority support, and feature tuning requests. Contact us for volume pricing.

Know what your agents can access

Download RootShield and run your first inspection in under 60 seconds. Free forever.