Bot Lock
A free MIT-licensed MCP server and security self-assessment for teams hardening AI agents against prompt injection, tool abuse, and audit
Are you the maker? Claim this listing to keep info, pricing and screenshots current. Verified via your tool's domain email.

Bot Lock is the right starting point for a solo developer or small team that wants a structured, research-backed way to think through AI agent security without spending anything upfront. The free tier is genuinely useful, but the $149 Pro tier currently ships no Pro-only files, which is an unusual honesty move that also means you are paying for future intent. Teams that need runtime enforcement, active threat detection, or integrations beyond a local stdio MCP server will find the tooling too thin compared to dedicated agent security platforms.
What is Bot Lock?
Bot Lock is an AI agent security kit from AgentHive Inc for teams running AI agents with tool access. The idea is simple: least privilege, audit and deny-by-default tools instead of system-prompt promises.
At its center is the Bot Lock MCP server, a free, MIT-licensed local Model Context Protocol server. It gives each agent an Ed25519 identity, keeps credentials in an AES-256-GCM vault, writes a signed, hash-chained audit log, checks every tool call against deny-by-default scopes, and includes a kill switch. It runs locally over stdio, works with any MCP client, and the source is on GitHub at PalmCoast/bot-lock.
Alongside the server, the free Bot Lock Check is an interactive self-assessment that runs offline in the browser.
How we scored Bot Lock
Capability lands at 14 because the product covers a real and important problem space but the actual enforcement surface is narrow: a local stdio MCP server with no cloud layer, no active detection, and a Pro tier that ships no additional functionality today. Ease of use scores 18 because the free Check requires no account and runs offline, the pricing is simple, and the one-time checkout removes subscription friction. Value scores 16 because the free tier and $49 Field Kit are genuinely fair for what they deliver, but the $149 Pro tier charging $100 more for identical content is a real value gap that pulls the sub-score down. Delivery scores 10 because there is no independent security audit of the cryptographic implementation, no external user sentiment to draw on, and the Pro tier's honest admission of no Pro-only files is a delivery shortfall even if disclosed transparently.
Pros and cons
What we liked
- The MCP server is genuinely open-source (MIT license, source on GitHub at PalmCoast/bot-lock) with real cryptographic controls: Ed25519 identity, AES-256-GCM vault, and a signed hash-chained audit log.
- The Bot Lock Check runs entirely in the browser with no account required, scored against ten weighted themes from 20 AI security sources, making it a zero-friction first audit for any team.
- One-time pricing ($49 Field Kit, $149 Pro) with no subscription means a small team can buy the playbook once and apply it without ongoing cost pressure.
Where it falls short
- The $149 Pro tier explicitly ships no Pro-only files today, meaning buyers are paying $100 more than Field Kit for the same playbook content and a stated intention to support future development. This is disclosed honestly but is a real gap.
- The MCP server runs locally over stdio only, with no cloud-hosted enforcement, no dashboard, and no active detection. Teams that need runtime threat interception rather than configuration-time controls get nothing here that a well-written config file could not approximate.
- No documented test coverage beyond the GitHub note of 23/23 Vitest tests on the MCP module, and no third-party security audit or independent validation of the cryptographic implementation is publicly referenced.
Key features
Bot Lock pricing
Two free tiers ($0): the MIT-licensed MCP server and the browser-based Bot Lock Check. Field Kit is $49 one-time via Stripe, covering the full playbook plus policy YAML templates. Pro is $149 one-time, which currently includes the same playbook as Field Kit with no Pro-only files yet.
| Plan | Price | Who it is for |
|---|---|---|
| Free | $0 | Bot Lock MCP server (MIT-licensed, runs locally), Bot Lock Check (browser-based, offline-capable), weighted theme scoring, and a shareable risk snapshot. |
| Field Kit | $49 | Full Bot Lock Playbook, policy YAML for deny-by-default tools, MCP allowlist, secrets and kill-switch templates, and a 30-day adoption plan. One-time Stripe checkout. |
| Pro | $149 | Everything in Field Kit. Same playbook chapters covering agent identity (NHI), vault issuance and audience binding, and audit. Backs the free MIT MCP server. No Pro-only files at time of review. One-time Stripe checkout. |
Pricing reflects what we saw at time of review (2026-10). Always confirm current pricing on the tool's own site.
Who should use Bot Lock?
A backend developer or small engineering team shipping their first LLM-powered agent with tool access will get real value from the free tier alone. The Bot Lock Check gives a structured, weighted audit against the ten most-discussed AI agent risks, and the MCP server provides concrete cryptographic controls that a system prompt simply cannot. For a team that has never formally thought through agent identity, scope, or audit logging, this is a low-friction starting point.
Teams that need active runtime threat detection, a cloud-hosted enforcement layer, or integrations beyond a local stdio server should look elsewhere. Qveris, which is in our directory, connects AI agents to real-world APIs through a single protocol and may suit teams whose primary concern is safe, controlled API access at scale rather than local identity and audit primitives.
Skip it if: Teams needing active runtime threat detection or cloud-hosted enforcement
Bot Lock alternatives
Frequently asked questions
Is the MCP server really free and open source?+
Yes. The Bot Lock MCP server is MIT-licensed and the source is publicly available on GitHub at PalmCoast/bot-lock. It runs locally over stdio with no cloud dependency.
What do I actually get for $149 Pro versus $49 Field Kit?+
At the time of this review, both tiers deliver the same playbook content. The Pro tier is explicitly described on the pricing page as having no Pro-only files yet, and is positioned as a way to financially support the free MCP server.
Does Bot Lock require an account or internet connection to use the Check?+
No. The Bot Lock Check runs entirely in the browser and is described as offline-capable. No account is needed to run it or generate a risk snapshot.
What AI security threats does Bot Lock address?+
The product covers ten weighted themes: prompt injection and jailbreak (16/20), logging and audit (16/20), least privilege and IAM (12/20), excessive agency (11/20), agent tool abuse (11/20), MCP supply chain (11/20), secrets management (10/20), data exfiltration (9/20), guardrails and I/O filtering (9/20), and token delegation and OAuth (9/20).
Does Bot Lock replace a red-team security audit?+
No, and the product says so directly. The site states that Bot Lock reduces agent risk when layered controls are applied but does not guarantee zero successful injections and does not replace authorized red-team verification.
What MCP clients does the Bot Lock server work with?+
The server runs over stdio and is described as compatible with any MCP client. No specific client integrations or exclusions are listed on the product page.
More AI Coding & Dev Tools
See all categoriesGet your tool listed on 300+ directories.
One listing here is a strong start. But the founders who get discovered everywhere are listed everywhere. Our sister site, Free AI Directories, submits your tool to 300+ AI directories for you, every single one by hand, by a real person.
It is a one-time payment of $49, no subscription, and you can follow along as the submissions land. Prefer the slow route? The same site keeps a free list of 450+ directories you can work through yourself.
Get my tool listed on 300+ directoriesOne-time payment, no subscription · 100% human submissions · Free list of 450+ directories included.