Superagent

Superagent

Superagent runs autonomous security workers that scan GitHub PRs, patch what they find, and guard what your coding agents read and do.

97/100Safe BetFree · from $499/moFreemium

If your team ships through GitHub and lets agents touch the codebase, Superagent is unusual in that it closes the loop — it patches what it finds rather than emailing you a CVE list, and the scheduled Secure Dependency Updates run (daily, weekly, or monthly, with vulnerability/version scope) is the part that quietly replaces a manual upgrade backlog. Two things to model before you buy. First, you have to live on GitHub; every worker is GitHub-shaped. Second, credit burn on private repos: Red Team reports cost 500 credits each, so one report can consume a full Starter month at $499/mo, and Growth at $1,499/mo only buys four. Annual paid plans carry 20% more credits and are billed upfront.

Verified 10d ago · liveness 97/100 · cite: rightaichoice.com/tools/superagent

Best for
  • Open-source maintainers who want free, unlimited security scanning and automated patch PRs on public repos
  • GitHub-native engineering teams already running Cursor, Claude Code, or Codex CLI
  • Security leads who need control over what agents read and do — runtime guardrails plus context scoring
  • Teams whose dependency backlog is out of control and want scheduled, policy-checked upgrade PRs
Not ideal for
  • Teams on GitLab, Bitbucket, or other non-GitHub platforms — the entire product is GitHub-shaped.
  • Organizations that require human-authored patches and a manual remediation review gate on every fix.
  • Simple codebases that only need CVE alerting — Dependabot covers that free, without credit accounting.
Visit Website

AdvancedOpen-source maintainers: minutes — install the Superagent Security GitHub App on a public repo and PR Security begins reviewing; unlimited usage is free. Private-repo teams on Starter or Growth: same-day for PR Security and scheduled dependency runs, though vulnerability-scoped runs need the Dependabot alerts read-only permission granted first. Agent-guardrail rollouts take longer, because youWeb · API · PluginAPI available4.5k viewsVerified 10d ago
Pricing
Free · from $499/mo
FreemiumFree tier5 plans5 hidden costs
Learning curve
Advanced
Open-source maintainers: minutes — install the Superagent Security GitHub App on a public repo and PR Security begins reviewing; unlimited usage is free. Private-repo teams on Starter or Growth: same-day for PR Security and scheduled dependency runs, though vulnerability-scoped runs need the Dependabot alerts read-only permission granted first. Agent-guardrail rollouts take longer, because you
Runs on
WebAPIPlugin
API available · 13 integrations
Who it's for
Open-source maintainerPlatform engineer with a stale dependency backlogSecurity lead at an AI product company
Live sentiment
Is Superagent actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip Superagent if your repositories live on GitLab or Bitbucket, or if you only need free CVE alerting without credit-based accounting — Dependabot already covers that case.

The 30-second take
Biggest gripe

Red Team reports cost 500 credits each, so a single report consumes half of a $499/mo Starter month's 500 credits or five times the free tier's 100 monthly credits.

Price reality

Free for public repositories with unlimited usage, and $0/mo for 100 private credits, so solo maintainers and early startups pay nothing. Starter at $499/mo (500 credits) and Growth at $1,499/mo (2,000 credits) sit well above Dependabot, which is free but only alerts — Superagent's price buys authored patches. Scale starts at $3,999/mo for 6,000 credits. Annual paid plans include 20% more credits and are billed upfront; credits refresh monthly.

In short

Superagent — Superagent runs autonomous security workers that scan GitHub PRs, patch what they find, and guard what your coding agents read and do. Best for Open-source maintainers who want free, unlimited security scanning and automated patch PRs on public repos, GitHub-native engineering teams already running Cursor, Claude Code, or Codex CLI, Security leads who need control over what agents read and do — runtime guardrails plus context scoring. Free to start; paid plans from $499/mo.

What's new in Superagent

Checked yesterday

Across the latest 6 updates: 2 feature updates, 2 launches, 1 community discussion and 1 news mention.

Viability Score

97/100
Safe Bet

How well maintained and how widely used is Superagent? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
90
Traction
not measured
Site health
95
User sentiment
not measured
What the vendor publishes
100

Last calculated: October 2026

How we score →

Key Features

  • PR security scans that block risky code and untrusted contributors before merge
  • Secure dependency updates that generate manifest and lockfile patch PRs on a daily, weekly, or monthly schedule
  • Dependency run scoping for vulnerabilities, direct version updates, or both
  • Pinned Dependabot tooling run in an isolated sandbox to evaluate package changes
  • Updates blocking on supply chain policy are withheld before a pull request opens
  • Automated PR fixes for vulnerabilities caught during review
  • Inline review comments and GitHub check runs on pull requests
  • Contributor trust scoring with patch-level safety assessment
  • CLA templates, signing bot, and version control (Agreements)
  • Runtime Guardrails that block destructive agent actions locally
  • Context Guardrails scoring web pages, email, files, agent skills, and MCP repositories
  • Context Guardrails scanning inbound SMS and WhatsApp text for phishing and prompt injection
  • Package scans for npm, PyPI, Go, RubyGems, and GitHub Actions
  • Self-serve red teaming for apps, repos, agents, models, and packages
  • Delegated PR review access for specific GitHub users and bots like github-actions[bot]

About Superagent

FreemiumAdvancedAPI availableWeb · API · Plugin

Superagent is an automated security platform built around GitHub-native teams that ship with coding agents. Instead of filing alerts into a dashboard, it runs "security workers" that each own one job end to end: PR Security (reviewing code, workflow, dependency, and contributor risk before merge), Secure Dependency Updates (turning vulnerable dependencies into tested, policy-cleared pull requests on a daily, weekly, or monthly schedule), Red Team (finding and reproducing the attack paths an attacker would chain across applications, agents, repos, models, and packages), and Agent Guardrails (Context Guardrails scoring what an agent reads, Runtime Guardrails constraining what it does locally). Findings are converted into code: inline review comments, GitHub check runs, and manifest/lockfile patch PRs, not tickets. Coverage reaches past the repository. Context Guardrails scores web pages, email, files, npm/PyPI/Go/RubyGems/GitHub Actions packages, agent skills, public GitHub MCP repositories, and — as of September 2026 — inbound SMS and WhatsApp text for phishing, prompt injection, and social engineering before an agent follows a link, though message attachments are not scanned. Public repositories are free with unlimited usage and can embed a README shield showing PR coverage and scan counts without exposing open findings. Private repositories start at $0 for 100 credits a month and scale through credit-based tiers; every plan includes every Superagent product, API and MCP access, and unlimited seats. Credits are consumed per product — 1 per PR scan, 500 per Red Team report, 1 per Context Guardrails item checked — while Contributor Trust, Agreements, and Runtime Guardrails are included at no credit cost. Built for maintainers, platform engineers, and security leads who already ship through GitHub and agents like Cursor, Claude Code, and Codex. Backed by Y Combinator; the vendor says it is used by 3,000+ open-source projects.

Behind the Verdict

The pitch that separates Superagent from a conventional scanner is that each worker owns one job end to end and returns code rather than a finding row. PR Security reviews code, workflow, dependency, and contributor risk before merge and can block risky changes and untrusted contributors. Secure Dependency Updates — the newest worker, shipped September 11, 2026 — finds available dependency versions, runs pinned Dependabot tooling in an isolated sandbox, evaluates supported package changes, and opens manifest and lockfile pull requests on a daily, weekly, or monthly schedule; updates that block on supply chain policy are withheld before a PR ever opens. A follow-up on September 13 added scope selection: vulnerability remediation (which requires Dependabot alerts: read-only on the Superagent Security GitHub App), direct version updates, or both, with vulnerability remediation as the default. Red Team maps the exploit paths an attacker would actually chain; the dotenvx customer story describes it chaining vulnerabilities the way a real kill chain builds, and patching them before a third-party scanner flagged the same issue. The guardrail story is the second half. Runtime Guardrails constrain what a coding agent is allowed to do locally, while Context Guardrails score what it consumes across five origins: web pages (domain identity, redirect chains, hidden DOM, rendered text), email (sender authentication, phishing and injection patterns, attachments, outbound links), files (public text and PDFs, with file bytes never stored), agent skills (GitHub publisher identity, requested capabilities, install hooks — skill files are treated as untrusted data and never executed), and public GitHub MCP repositories (static review of tool descriptions, schemas, instructions, hooks, and secrets; Superagent never connects to a live MCP endpoint). Every scan returns a 0–100 score, a safe/caution/suspicious/dangerous verdict, and a confidence level, and cached results are reused across organizations. The September 7, 2026 changelog extended this to inbound SMS and WhatsApp text — checking message text and outbound HTTPS links for phishing, prompt injection, and social engineering before an agent follows a link. Attachments are explicitly not scanned, and that is the sharpest edge of the messaging coverage. Package scans landed August 17 for npm, PyPI, Go, RubyGems, and GitHub Actions, using the same supply chain pipeline as PR checks, with scan failures failing closed rather than returning a safe result. The operational details are where teams will actually feel this. PR review access can be delegated to exact GitHub logins, including automation bots such as github-actions[bot] (September 10, 2026), so a bot can comment "@superagent review" even when automatic scans are off — though Superagent's own bots are blocked to prevent review loops, and the product is designed so people approve consequential changes. Public repos can embed a shield and security card showing

Researching Superagent? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas Superagent actually fits — and what changes day-one when you adopt it.

Open-source maintainer

A public repo gets a pull request from a first-time contributor with a dependency bump. PR Security runs, scores the contributor's patch-level safety, leaves inline review comments and a GitHub check run, and blocks the merge until the risky change is addressed. You add the README shield so visitors can see PR coverage and scan counts without exposing findings.

Outcome: Risky changes stop at the merge button instead of landing in main, and you pay nothing because public repositories are free with unlimited usage.

Platform engineer with a stale dependency backlog

You set Secure Dependency Updates to a weekly schedule and pick the Vulnerabilities scope. Superagent runs pinned Dependabot tooling in an isolated sandbox, evaluates the package changes, and opens manifest and lockfile PRs only for proposals that pass supply chain policy; anything blocking is withheld before the PR opens.

Outcome: The upgrade backlog turns into reviewable pull requests on a cadence you set, instead of a manual triage session every quarter.

Security lead at an AI product company

You put Context Guardrails in front of what your agent consumes and Runtime Guardrails where it runs. Web pages, files, skills, and MCP repos get scored 0-100 with a safe/caution/suspicious/dangerous verdict; inbound SMS and WhatsApp text is scored for phishing and prompt injection before the agent follows a link.

Outcome: Agents keep full capability without inheriting hostile input, and PII/PHI rules are enforced at the point the agent acts rather than in a downstream log.

Use Cases

  • Automating security fixes for pull requests in your GitHub repos.
  • Red teaming your AI agents and applications before launch.
  • Ensuring coding agents follow safety rules and don't perform catastrophic actions.
  • Verifying contributor trust and CLA compliance before merging code.
  • Assessing the security of third-party packages and CLIs before adoption.
  • Screening inbound SMS and WhatsApp messages for phishing and prompt injection before an agent follows a link.
  • Clearing a dependency backlog with scheduled, policy-checked upgrade PRs instead of manual triage.

Models Under the Hood

Security-One 27B

as of 2026-10-09

Limitations

  • Superagent is a security platform for GitHub-native AI development, covering PR scans, secure dependency updates, contributor trust, runtime and context guardrails, and red teaming.
  • It is a developer/security tool, so effective use assumes GitHub-centric engineering expertise.
  • Coverage gaps are documented by the vendor: Context Guardrails scores SMS and WhatsApp message text and outbound links, but media and attachments are not scanned; MCP repository review is static and Superagent never connects to a live MCP endpoint; skill files are never executed, only inspected.
  • Infrastructure coverage — developer machines, agent hosts, CI runners, and cloud workloads — is listed in the docs as coming soon, not available today.
  • Pricing is tiered by private credits (free for open source, then paid free/starter/growth/scale plans) while every plan includes full product, API, and MCP access.

as of 2026-09-28

Verification history

We have re-verified Superagent 19 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  2. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  3. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  4. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  6. — re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it

Showing the 6 most recent of 19 verification passes.

Free to cite with attribution — this page re-verifies continuously.

12-month cost

Project the real annual outlay, including the implied monthly cost when only an annual tier is published.

Annual total
Free
Over 12 months
Effective monthly
—
—

Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.

Plans compared

For each published Superagent tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.

Open Source

$0

Free

$0/mo

Ideal for

Solo developer or small team putting their first private repository under PR Security who wants every product included before spending anything.

What this tier adds

Starting private tier: 100 credits a month, every Superagent product plus API and MCP access, unlimited seats, credits refresh monthly.

Starter

$499/mo

Ideal for

A team securing its first private repositories at moderate PR volume, without heavy red-teaming needs.

What this tier adds

Raises the monthly allowance from 100 to 500 credits, which funds 500 PR scans or a single 500-credit Red Team report.

Growth

$1,499/mo

Ideal for

Teams running security continuously through development, with dependency updates and PR scans across several active repos.

What this tier adds

2,000 credits a month versus Starter's 500 — four Red Team reports, or 2,000 PR scans, with the same full product and unlimited seats.

Scale

starts at $3,999/mo

Ideal for

High-volume security programs using red teaming and scheduled dependency runs across many private repositories.

What this tier adds

6,000 credits a month starting at $3,999/mo, the top private tier, with the same every-product inclusion and unlimited seats.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • Red Team reports cost 500 credits each, so a single report consumes half of a $499/mo Starter month's 500 credits or five times the free tier's 100 monthly credits.
  • Credits refresh monthly and do not appear to roll over, so unused private credits from a quiet month are not banked for a heavier one.
  • Annual paid plans carry 20% more credits but are billed upfront, so the discount is paid for in cash flow rather than in a lower monthly rate.
  • Moving to Scale starts at $3,999/mo for 6,000 credits, meaning a heavy Red Team program is priced separately from the PR-scan volume most teams actually feel.
  • Vulnerability-scoped dependency runs require the Superagent Security GitHub App to hold Dependabot alerts: read-only permission, an extra permission grant some security teams will need to review and approve.

Where the pricing makes sense

The company stage and team size where Superagent's pricing actually pencils out — and where peers do it cheaper.

Free for public repositories with unlimited usage, and $0/mo for 100 private credits, so solo maintainers and early startups pay nothing. Starter at $499/mo (500 credits) and Growth at $1,499/mo (2,000 credits) sit well above Dependabot, which is free but only alerts — Superagent's price buys authored patches. Scale starts at $3,999/mo for 6,000 credits. Annual paid plans include 20% more credits and are billed upfront; credits refresh monthly.

Setup time & first value

How long it actually takes to get something useful out of Superagent — broken out by persona, not the marketing-page minute.

Open-source maintainers: minutes — install the Superagent Security GitHub App on a public repo and PR Security begins reviewing; unlimited usage is free. Private-repo teams on Starter or Growth: same-day for PR Security and scheduled dependency runs, though vulnerability-scoped runs need the Dependabot alerts read-only permission granted first. Agent-guardrail rollouts take longer, because you

Switching to or from Superagent

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • →From Dependabot alerts: point Superagent's Secure Dependency Updates at the same repos and let scheduled runs open the patches Dependabot only reported.
  • →From a manual PR review checklist: enable PR Security scans, then grant exact GitHub logins or bots review access if you need automations to trigger scans.
  • →From a spreadsheet of contributor CLAs: move to Agreements templates and signing bot so CLA state is checked at merge time.
  • →From ad-hoc prompt-injection testing: replace it with Context Guardrails scoring across web, email, files, skills, and MCP repos.
Migrating out
  • ↗To Dependabot alone: turn off scheduled dependency runs if you only need CVE alerts and are willing to author the patches yourself.
  • ↗To a host-level security agent: Superagent does not cover infrastructure yet — its docs list developer machines, CI runners, and cloud workloads as coming soon.

Integrations

Resources & Guides

Tutorials & Learning

YouTube returned 6 videos for “Superagent”, and we withheld 6: 6 could not be judged, because “Superagent” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about Superagent.

Popular in Application & Code Security

Snyk DeepCode AI

Snyk DeepCode AI

Snyk DeepCode AI finds, autofixes and prioritizes vulnerabilities in human-written and AI-generated code.

FreemiumTry
Mindgard

Mindgard

Mindgard automates AI red teaming to find, validate, and fix exploitable AI agent vulnerabilities.

Contact SalesTry
Coro

Coro

Coro consolidates endpoint, email, cloud and network security into one AI-agent platform that auto-remediates 95% of threats.

Contact SalesTry

Frequently Asked Questions

Used Superagent? Help shape our editorial sentiment research.