Go · npm · PyPI83Excellenthealth index

ShieldNet-360/prompt-gatePrompt Gate — privacy-first, on-device DLP for the AI era. Blocks unauthorized AI tools at the DNS layer and inspects content sent to approved tools for secrets/PII, entirely on-device.
Go · TypeScript★ 49Sep 6, 2026
Go83Excellenthealth index

peg/rampartOpen-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.
Go★ 83Sep 6, 2026
Go · npm83Excellenthealth index
xalgord/xalgorixAutonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Go · TypeScript★ 768Jul 17, 2026
npm · PyPI81Excellenthealth index
Agent-Threat-Rule/agent-threat-rulesOpen detection standard -- like Sigma, but for AI agents. 425 rules, shipped in Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H. 97.1% recall on NVIDIA garak. NIST OSCAL Path 1.
TypeScript★ 314↓ 9,370/moJul 16, 2026
Go81Excellenthealth index
airomhq/airomOpen-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 23, 2026
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026
node9-ai/node9-proxyThe Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.
TypeScript★ 209↓ 9,089/moJul 22, 2026
crates.io · npm77Goodhealth index
backbay-labs/clawdstrikeAI EDR for developer workstations and autonomous agent fleets. Build Swarm Detection & Response platforms with Clawdstrike.
TypeScript · Rust★ 285Aug 4, 2026
Go★ 1Jul 27, 2026
Go · Maven77Goodhealth index
seqra/seqraThe open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 110Jul 17, 2026
PyPI · npm75Goodhealth index
gautamvarmadatla/mcpsafetywardenMCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2,923/moAug 1, 2026
msaleme/red-team-blue-team-agent-fabric540 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, MCP tool-poisoning reproduction. v4.9.1
Python★ 20↓ 667/moJul 20, 2026

panguard-ai/panguard-aiOpen-source security platform for AI agents -- audits skills before install, monitors 24/7, shares threat intelligence across all users. | AI Agent 開源安全平台 -- 安裝前審計 skill、24/7 即時監控、社群共享威脅情報。
TypeScript★ 63↓ 1,214/moSep 5, 2026
Packagist73Goodhealth index

fissible/verdictDeterministic authorization boundary for laravel/ai agents — models propose, applications authorize.
PHP★ 2↓ 2,275/moAug 30, 2026
gumieri/nenyaA lightweight, highly secure AI API Gateway/Proxy written in Go. Acts as transparent middleware between local AI coding clients (OpenCode/Pi/Cursor) and upstream LLM providers (Gemini, DeepSeek, Zhipu z.ai).
Go★ 25Jul 24, 2026
Go · Python★ 12Jul 23, 2026
PyPI · npm71Goodhealth index
PrismorSec/prismorRuntime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/moJul 19, 2026
TypeScript★ 82↓ 3,814/moAug 6, 2026

Drakon-Systems-Ltd/ShieldCortex🧠🛡️ Complete memory & security for AI agents. Persistent storage, semantic search, prompt injection firewall, audit trail. One package.
TypeScript★ 25↓ 14.6K/moAug 22, 2026
Python★ 45↓ 1,793/moJul 17, 2026
goklab/guardvibeSecurity infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026

tiagosilva07/zyrax-guardAudit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 2Aug 28, 2026
famclaw/honeybadgerSecurity scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
PyPI63Moderatehealth index
manthanghasadiya/mcpsecAn AI-driven dynamic protocol fuzzer for the Model Context Protocol (MCP). Prove runtime exploitability by discovering state violations, transport crashes, and application-layer logic flaws (SSRF, LFI) before your AI agents do.
Python★ 22↓ 319/moJul 28, 2026
PyPI63Moderatehealth index
Python★ 7↓ 2,841/moAug 28, 2026
npm63Moderatehealth index
TypeScript · Swift★ 15↓ 2,863/moJul 29, 2026
PyPI62Moderatehealth index
Python★ 4↓ 2,911/moAug 18, 2026
Go★ 22Jul 21, 2026
PyPI60Moderatehealth index
Python★ 5Jul 20, 2026
npm60Moderatehealth index
TypeScript★ 0↓ 4,664/moJul 19, 2026