Go95Exceptionalhealth index
Go★ 20Jul 18, 2026
npm · Maven94Exceptionalhealth index

iflytek/skillhubSelf-hosted, open-source agent skill registry for enterprises. Publish & version skill packages, govern with RBAC and audit logs, deploy on-premise with Docker or Kubernetes.
Java · TypeScript★ 4,901↓ 3,673/moAug 28, 2026
npm91Excellenthealth index

xpert-ai/xpertXpertAI is an open-source platform for building, running, and evolving ai agents, providing extensible capabilities and infrastructure for diverse AI systems.
TypeScript · HTML★ 437↓ 7,676/moSep 5, 2026
PyPI · Go · npm90Excellenthealth index

cordum-io/cordumThe action firewall for AI agents. Enforce policy and human approval before risky tool calls, shell commands, workflows, and production changes, with auditable evidence.
Go · TypeScript · Python★ 494↓ 17/moAug 9, 2026
PyPI · npm89Excellenthealth index
NuGuardAI/nuguardopensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4,954/moJul 18, 2026
PyPI86Excellenthealth index

agentrust-io/trace-specTRACE: Trust Runtime Attestation and Compliance Evidence. Open attestation standard for agentic AI governance.
Python★ 24↓ 142.9K/moSep 6, 2026
npm · PyPI86Excellenthealth index

issdandavis/SCBE-AETHERMOOREGeometric AI governance and evaluation framework with a 14-layer security pipeline, semantic projection, and reproducible benchmark lanes.
Python · TypeScript★ 6↓ 4,607/moAug 26, 2026
PyPI86Excellenthealth index

vaaraio/vaaraAccountable Autonomy: open-source evidence layer that gates every AI agent tool call against your policy and writes a hash-chained record an auditor verifies offline, without trusting you. Root-agnostic; binds to TPM 2.0 / SEV-SNP when present. Your environment, no SaaS, no telemetry. AGPL-3.0.
Python★ 11↓ 6,460/moAug 22, 2026
Go83Excellenthealth index
Go★ 69Jul 21, 2026
Go81Excellenthealth index
airomhq/airomOpen-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 23, 2026
Go81Excellenthealth index
g8e-ai/g8eGovernance Architecture for Trustless Execution ⚖️
Go★ 7Jul 17, 2026
PyPI · npm81Excellenthealth index

sseshachala/conductaiAI agent governance for teams. Runtime firewalls tell you what happened; Conduct Guard controls what can happen — signed policy, verified chain, fail-closed by default. Ships with Router (LLM proxy), 20+ compliance packs, canvas UI, and a playbook engine.
Python · TypeScript★ 18↓ 3,824/moAug 29, 2026
Go · PyPI80Excellenthealth index

Goldziher/ai-rulezComplete AI development workflow for 19+ tools. Builtin rules, agents, and conventions out of the box. Generate native configs for Claude, Cursor, Copilot, Windsurf, Gemini, Codex and more.
Go★ 138Aug 25, 2026
npm · PyPI80Excellenthealth index
delimit-ai/delimit-mcp-serverThe merge gate for AI-written code, with signed, replayable attestation. Works across Claude Code, Codex, Cursor, and Gemini CLI.
Python · JavaScript★ 21↓ 3,625/moAug 3, 2026
npm80Excellenthealth index
lua-ai-global/governanceZero-dependency TypeScript SDK for AI agent governance: policy enforcement, injection detection, tamper-evident audit, and standards mapping (EU AI Act, OWASP, NIST, ISO 42001)
TypeScript★ 25↓ 3,545/moJul 26, 2026
Protocol-Wealth/pwos-coreOpen source compliance-first AI operating system for SEC-registered investment advisers. Apache 2.0 licensed with defensive patent grant.
TypeScript★ 3↓ 4,978/moJul 25, 2026
getaxonflow/axonflow-sdk-goOfficial Go SDK for AxonFlow — runtime control, MCP policy enforcement, approvals, and audit trails for production AI
Go★ 1Jul 23, 2026
Craig-Horton/ai-bvfOpen protocol for scoring AI investments. JSON Schema, scoring engine, MCP server. Spec under CC-BY-4.0.
HTML · TypeScript · JavaScript★ 0↓ 5,230/moJul 31, 2026

alizahidraja/isnadGrade every agent, scraper and model in a claim's chain — provenance, trust scoring and audit evidence for LLM pipelines
Python★ 37↓ 4,204/moAug 29, 2026

cendorhq/cendor-libs-jsProduction plumbing for LLM apps in TypeScript: context, cost, testing & governance primitives. Python-interoperable.
TypeScript★ 0↓ 12.9K/moAug 29, 2026
dativo-io/talonOpen-source AI governance gateway for EU teams: enforce PII, cost, model, data residency, and tool policies for LLMs and AI agents with signed evidence.
Go★ 10Jul 17, 2026
crates.io · npm77Goodhealth index
soapbucket/sbproxySelf-hosted AI gateway and LLM proxy. OpenAI-compatible API for OpenAI, Anthropic, Gemini, Bedrock and 60+ providers, or serve vLLM/llama.cpp on your GPUs. Keys, budgets, guardrails, semantic cache, MCP
Rust★ 47Jul 30, 2026
bookedsolidtech/reaZero-trust governance layer for Claude Code. Policy-enforced MCP gateway with autonomy controls, middleware chain, audit log, HALT kill-switch, and prompt-injection defense.
TypeScript · Shell★ 0↓ 1,950/moJul 27, 2026
comisai/comisOpen-source security-first runtime for AI agents that learn and act across sessions.
TypeScript★ 5Jul 20, 2026
crates.io · npm75Goodhealth index
runxhq/runxthe governed runtime for agent skill workflows, off the leash but on the record
Rust · TypeScript · HTML★ 72Jul 15, 2026
Keesan12/martin-loopMake AI coding agents safe to scale autonomously: assign work, cap spend, enforce policy, verify output, roll back failures, learn from loops, and prove ROI across every repo.
TypeScript · JavaScript★ 38↓ 3,459/moJul 19, 2026
PyPI · npm73Goodhealth index
aiexponenthq/license-compliance-checkerLicense Compliance Checker — Multi-ecosystem license + AI model scanner for EU AI Act Article 53 GPAI compliance. SBOM, SARIF, training-data risk. Apache 2.0.
Python · TypeScript★ 1↓ 258/moJul 27, 2026
gumieri/nenyaA lightweight, highly secure AI API Gateway/Proxy written in Go. Acts as transparent middleware between local AI coding clients (OpenCode/Pi/Cursor) and upstream LLM providers (Gemini, DeepSeek, Zhipu z.ai).
Go★ 25Jul 24, 2026
philpaz/recusalDeterministic governance for Claude and MCP tool calls. Pin approved capabilities, detect drift, and refuse unsafe or unapproved actions before execution. No model in the decision path.
Python★ 3↓ 2,854/moJul 27, 2026
abdelrahmannasr/yadflowYadflow (yad = يد, "hand") — the AI-driven SDLC where a human hand moves every gate. Gated, team, multi-repo: author → review → build, with a PR-driven review gate and a zero-dependency CLI. Ships as a BMAD module + 17 skills.
JavaScript · TypeScript★ 0↓ 8,420/moJul 16, 2026