# Bot Lock Review A free MIT-licensed MCP server and security self-assessment for teams hardening AI agents against prompt injection, tool abuse, and audit ## Editor's Score: 58/100 Capability lands at 14 because the product covers a real and important problem space but the actual enforcement surface is narrow: a local stdio MCP server with no cloud layer, no active detection, and a Pro tier that ships no additional functionality today. Ease of use scores 18 because the free Check requires no account and runs offline, the pricing is simple, and the one-time checkout removes subscription friction. Value scores 16 because the free tier and $49 Field Kit are genuinely fair for what they deliver, but the $149 Pro tier charging $100 more for identical content is a real value gap that pulls the sub-score down. Delivery scores 10 because there is no independent security audit of the cryptographic implementation, no external user sentiment to draw on, and the Pro tier's honest admission of no Pro-only files is a delivery shortfall even if disclosed transparently. ## Pros - The MCP server is genuinely open-source (MIT license, source on GitHub at PalmCoast/bot-lock) with real cryptographic controls: Ed25519 identity, AES-256-GCM vault, and a signed hash-chained audit log. - The Bot Lock Check runs entirely in the browser with no account required, scored against ten weighted themes from 20 AI security sources, making it a zero-friction first audit for any team. - One-time pricing ($49 Field Kit, $149 Pro) with no subscription means a small team can buy the playbook once and apply it without ongoing cost pressure. ## Cons - The $149 Pro tier explicitly ships no Pro-only files today, meaning buyers are paying $100 more than Field Kit for the same playbook content and a stated intention to support future development. This is disclosed honestly but is a real gap. - The MCP server runs locally over stdio only, with no cloud-hosted enforcement, no dashboard, and no active detection. Teams that need runtime threat interception rather than configuration-time controls get nothing here that a well-written config file could not approximate. - No documented test coverage beyond the GitHub note of 23/23 Vitest tests on the MCP module, and no third-party security audit or independent validation of the cryptographic implementation is publicly referenced. ## Pricing Freemium. A free tier is available. - Free: $0 - Field Kit: $49 - Pro: $149 Pricing reflects what we saw at the time of review (2026-10). Confirm current pricing on the official site. Category: AI Coding & Dev Tools (https://aitoolseekers.com/category/ai-coding-dev-tools) Official site: https://bot-lock.netlify.app/ Last verified by a human: 2026-10-08 Reviewed by a human at AI Tool Seekers, a hand-reviewed AI tools directory. Every listed tool is verified by a person before publishing. Scores are editorial opinions from a fixed rubric (capability, ease of use, value, delivery on promise) and cannot be bought; there is no pay-to-rank. Directory: https://aitoolseekers.com This review: https://aitoolseekers.com/tools/bot-lock Methodology: https://aitoolseekers.com/how-verification-works ## Verdict Bot Lock is the right starting point for a solo developer or small team that wants a structured, research-backed way to think through AI agent security without spending anything upfront. The free tier is genuinely useful, but the $149 Pro tier currently ships no Pro-only files, which is an unusual honesty move that also means you are paying for future intent. Teams that need runtime enforcement, active threat detection, or integrations beyond a local stdio MCP server will find the tooling too thin compared to dedicated agent security platforms. Best for: Solo developers and small teams doing a first AI agent security audit Not for: Teams needing active runtime threat detection or cloud-hosted enforcement ## Overview Bot Lock is an AI agent security kit from AgentHive Inc., built around a specific philosophy: enforce least privilege and deny-by-default at the infrastructure level rather than relying on system-prompt instructions that an attacker can override. The product has four components: a free MIT-licensed local MCP server, a free browser-based self-assessment called Bot Lock Check, a $49 one-time Field Kit playbook, and a $149 Pro tier that currently ships the same playbook content as Field Kit. The MCP server is the most technically concrete piece. It runs locally over stdio, works with any MCP client, and provides Ed25519 agent identity, AES-256-GCM credential storage, a signed hash-chained audit log, deny-by-default scope checks, and a kill switch. The source is on GitHub at PalmCoast/bot-lock. The Bot Lock Check is a weighted self-assessment scored against ten AI security themes drawn from 20 educational sources, with prompt injection and logging each weighted 16/20 and least privilege at 12/20. What separates Bot Lock from general-purpose agent platforms is its narrow, honest scope. The site explicitly states it reduces agent risk when you apply layered controls and does not guarantee zero successful injections or replace authorized red-team verification. That kind of disclaimer is rare and signals a product built for practitioners who already understand the threat model, not one selling magic. The tradeoff is that the product is thin: no cloud dashboard, no active detection, no integrations beyond stdio MCP, and the Pro tier is openly a patronage purchase today. ## Who should use it A backend developer or small engineering team shipping their first LLM-powered agent with tool access will get real value from the free tier alone. The Bot Lock Check gives a structured, weighted audit against the ten most-discussed AI agent risks, and the MCP server provides concrete cryptographic controls that a system prompt simply cannot. For a team that has never formally thought through agent identity, scope, or audit logging, this is a low-friction starting point. Teams that need active runtime threat detection, a cloud-hosted enforcement layer, or integrations beyond a local stdio server should look elsewhere. Qveris, which is in our directory, connects AI agents to real-world APIs through a single protocol and may suit teams whose primary concern is safe, controlled API access at scale rather than local identity and audit primitives. ## FAQ Q: Is the MCP server really free and open source? A: Yes. The Bot Lock MCP server is MIT-licensed and the source is publicly available on GitHub at PalmCoast/bot-lock. It runs locally over stdio with no cloud dependency. Q: What do I actually get for $149 Pro versus $49 Field Kit? A: At the time of this review, both tiers deliver the same playbook content. The Pro tier is explicitly described on the pricing page as having no Pro-only files yet, and is positioned as a way to financially support the free MCP server. Q: Does Bot Lock require an account or internet connection to use the Check? A: No. The Bot Lock Check runs entirely in the browser and is described as offline-capable. No account is needed to run it or generate a risk snapshot. Q: What AI security threats does Bot Lock address? A: The product covers ten weighted themes: prompt injection and jailbreak (16/20), logging and audit (16/20), least privilege and IAM (12/20), excessive agency (11/20), agent tool abuse (11/20), MCP supply chain (11/20), secrets management (10/20), data exfiltration (9/20), guardrails and I/O filtering (9/20), and token delegation and OAuth (9/20). Q: Does Bot Lock replace a red-team security audit? A: No, and the product says so directly. The site states that Bot Lock reduces agent risk when layered controls are applied but does not guarantee zero successful injections and does not replace authorized red-team verification. Q: What MCP clients does the Bot Lock server work with? A: The server runs over stdio and is described as compatible with any MCP client. No specific client integrations or exclusions are listed on the product page.