PyPI · crates.io · npm93Exceptionalhealth index

hashgraph-online/hol-guardOpen-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/moSep 5, 2026
Go93Exceptionalhealth index
mindburn-labs/helm-ai-kernelFail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 53Jul 17, 2026
PyPI · RubyGems90Excellenthealth index
Python★ 155↓ 2,902/moAug 25, 2026
Go90Excellenthealth index
mindburn-labs/helm-ossFail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 53Jul 18, 2026
crates.io90Excellenthealth index
nolabs-ai/nonoSandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,016Jul 16, 2026
crates.io89Excellenthealth index
Rust★ 3,036Jul 17, 2026
crates.io89Excellenthealth index
lukehinds/nonoSandbox any AI agent in seconds - zero setup, zero latency.
Rust★ 3,047Jul 19, 2026
PyPI88Excellenthealth index
datafog/datafog-pythonOffline PII firewall for AI agents and LLM apps: fast local detection and redaction, Claude Code hook, LiteLLM guardrail. Zero network calls, one dependency.
Python★ 67↓ 34K/moJul 16, 2026
npm88Excellenthealth index
garudex-labs/caracal🐾 Authority, not credentials, for AI agents: policy-approved actions, delegation that can only narrow, instant revocation, tamper-evident audit.
TypeScript · Go★ 155Jul 15, 2026
npm86Excellenthealth index

emiliaprotocol/emilia-protocolAuthority control plane for autonomous work. EMILIA Gate enforces finite customer-owned mandates at protected executor boundaries; the open protocol keeps evidence verifiable.
TypeScript · HTML★ 649↓ 1,109/moSep 5, 2026
PyPI86Excellenthealth index

vaaraio/vaaraAccountable Autonomy: open-source evidence layer that gates every AI agent tool call against your policy and writes a hash-chained record an auditor verifies offline, without trusting you. Root-agnostic; binds to TPM 2.0 / SEV-SNP when present. Your environment, no SaaS, no telemetry. AGPL-3.0.
Python★ 11↓ 6,460/moAug 22, 2026
Go83Excellenthealth index

peg/rampartOpen-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.
Go★ 83Sep 6, 2026
npm · PyPI81Excellenthealth index
Agent-Threat-Rule/agent-threat-rulesOpen detection standard -- like Sigma, but for AI agents. 425 rules, shipped in Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H. 97.1% recall on NVIDIA garak. NIST OSCAL Path 1.
TypeScript★ 314↓ 9,370/moJul 16, 2026
Go81Excellenthealth index

cfgaudit/cfgauditAI agent configuration security auditor - find misconfigurations in Claude Code, Cursor, and other AI tools
Go★ 7Aug 23, 2026
npm80Excellenthealth index
lua-ai-global/governanceZero-dependency TypeScript SDK for AI agent governance: policy enforcement, injection detection, tamper-evident audit, and standards mapping (EU AI Act, OWASP, NIST, ISO 42001)
TypeScript★ 25↓ 3,545/moJul 26, 2026
node9-ai/node9-proxyThe Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.
TypeScript★ 209↓ 9,089/moJul 22, 2026
Asymptote-Labs/agent-beaconAgent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, or in the cloud.
Go★ 293Jul 15, 2026

Synapsor/Synapsor-RunnerLet AI agents query and update Postgres/MySQL without raw SQL, unrestricted schema access, or database credentials in the model; writes stay reviewed.
TypeScript · JavaScript★ 2↓ 5,822/moAug 22, 2026
crates.io · npm77Goodhealth index
backbay-labs/clawdstrikeAI EDR for developer workstations and autonomous agent fleets. Build Swarm Detection & Response platforms with Clawdstrike.
TypeScript · Rust★ 285Aug 4, 2026
Go★ 1Jul 27, 2026
thewaltero/mythos-routerThe leaked Anthropic reasoning protocol. Running locally. Zero-drift coding with Strict Write Discipline and adaptive Claude Opus 4.8 thinking. Mythos
TypeScript★ 279↓ 579/moJul 17, 2026
comisai/comisOpen-source security-first runtime for AI agents that learn and act across sessions.
TypeScript★ 5Jul 20, 2026
PyPI · npm75Goodhealth index
gautamvarmadatla/mcpsafetywardenMCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2,923/moAug 1, 2026
msaleme/red-team-blue-team-agent-fabric540 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, MCP tool-poisoning reproduction. v4.9.1
Python★ 20↓ 667/moJul 20, 2026
Go · Python★ 12Jul 23, 2026
philpaz/recusalDeterministic governance for Claude and MCP tool calls. Pin approved capabilities, detect drift, and refuse unsafe or unapproved actions before execution. No model in the decision path.
Python★ 3↓ 2,854/moJul 27, 2026
PyPI · npm71Goodhealth index
PrismorSec/prismorRuntime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/moJul 19, 2026

tiagosilva07/zyrax-guardAudit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 2Aug 28, 2026
lelu-ai/leluOpen source authorization engine for AI agents. Confidence-aware gating · Human-in-the-loop review · Policy-as-code · Full audit trail
TypeScript · Go★ 43Jul 16, 2026
npm63Moderatehealth index
TypeScript · Swift★ 15↓ 2,863/moJul 29, 2026