npm · Go · crates.io96卓越健康指数

microsoft/agent-governance-toolkitAI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 6,138↓ 14.7K/月2026年8月28日
sattyamjjain/agent-audit-kitStatic scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/月2026年8月2日
Python★ 155↓ 2,902/月2026年8月25日

cordum-io/cordumThe action firewall for AI agents. Enforce policy and human approval before risky tool calls, shell commands, workflows, and production changes, with auditable evidence.
Go · TypeScript · Python★ 494↓ 17/月2026年8月9日

issdandavis/SCBE-AETHERMOOREGeometric AI governance and evaluation framework with a 14-layer security pipeline, semantic projection, and reproducible benchmark lanes.
Python · TypeScript★ 6↓ 4,607/月2026年8月26日

JKHeadley/instarPersistent Claude Code agents with scheduling, sessions, memory, and Telegram.
TypeScript★ 77↓ 157.9K/月2026年9月5日
lua-ai-global/governanceZero-dependency TypeScript SDK for AI agent governance: policy enforcement, injection detection, tamper-evident audit, and standards mapping (EU AI Act, OWASP, NIST, ISO 42001)
TypeScript★ 25↓ 3,545/月2026年7月26日
node9-ai/node9-proxyThe Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.
TypeScript★ 209↓ 9,089/月2026年7月22日
IgorGanapolsky/ThumbGateThumbGate Pre-Action Checks derive rules from repeated failures, flag risky tool calls, hard-block detected secret leaks, and block matches in strict mode.
JavaScript · HTML★ 24↓ 4,611/月2026年7月19日

alizahidraja/isnadGrade every agent, scraper and model in a claim's chain — provenance, trust scoring and audit evidence for LLM pipelines
Python★ 37↓ 4,204/月2026年8月29日
bookedsolidtech/reaZero-trust governance layer for Claude Code. Policy-enforced MCP gateway with autonomy controls, middleware chain, audit log, HALT kill-switch, and prompt-injection defense.
TypeScript · Shell★ 0↓ 1,950/月2026年7月27日
gautamvarmadatla/mcpsafetywardenMCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2,923/月2026年8月1日
Keesan12/martin-loopMake AI coding agents safe to scale autonomously: assign work, cap spend, enforce policy, verify output, roll back failures, learn from loops, and prove ROI across every repo.
TypeScript · JavaScript★ 38↓ 3,459/月2026年7月19日
aiexponenthq/license-compliance-checkerLicense Compliance Checker — Multi-ecosystem license + AI model scanner for EU AI Act Article 53 GPAI compliance. SBOM, SARIF, training-data risk. Apache 2.0.
Python · TypeScript★ 1↓ 258/月2026年7月27日

auspexai/workerAuspexAI volunteer worker for donating compute to AI research
Python★ 0↓ 628/月2026年8月22日
b7n0de/proofbundleOffline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
Python★ 2↓ 6,574/月2026年7月23日
gumieri/nenyaA lightweight, highly secure AI API Gateway/Proxy written in Go. Acts as transparent middleware between local AI coding clients (OpenCode/Pi/Cursor) and upstream LLM providers (Gemini, DeepSeek, Zhipu z.ai).
Go★ 252026年7月24日
philpaz/recusalDeterministic governance for Claude and MCP tool calls. Pin approved capabilities, detect drift, and refuse unsafe or unapproved actions before execution. No model in the decision path.
Python★ 3↓ 2,854/月2026年7月27日
alexandriashai/cbrowserCognitive Browser: The browser automation that thinks. Constitutional safety • Persona UX testing • Natural language interface • Self-healing selectors • Built for AI agents
TypeScript · JavaScript★ 18↓ 2,900/月2026年7月17日
Python★ 0↓ 9,632/月2026年7月16日
Python★ 45↓ 1,793/月2026年7月17日

fathom-lab/styxxVerification for the agent era. Your coding agent's PR summary cannot lie about its diff - one CI line. Plus the research: the first map of which AI minds can read each other. Every claim machine-verified against committed receipts, negatives included. pip install styxx
Python★ 14↓ 2,231/月2026年8月19日
CognitiveThoughtEngine/constitutional-agent-governanceThe WHY layer for AI agents: six constitutional gates + 12 hard constraints, plus cross-session risk composition — catches agents that pass every individual gate but accumulate risk across a sequence (stateless engines can't). pip install constitutional-agent
Python★ 0↓ 331/月2026年7月27日
Go · TypeScript★ 82026年7月19日

kahramanemir/VallumSecurity boundary CLI proxy between AI coding agents and your shell — redacts secrets, neutralizes prompt injection, wraps untrusted terminal output, and audits every command. Single Rust binary.
Rust★ 5↓ 159/月2026年9月6日
Python★ 4↓ 2,911/月2026年8月18日
Go★ 222026年7月21日
veldtlabs/veldt-kyaKYA (Know Your Agents) — Open-source trust, governance, and evidentiary assurance infrastructure for autonomous systems. Built on KYP (Know Your Principal), a unified trust model for human users, AI agents, service accounts, and machine identities.
Python★ 2↓ 5,683/月2026年7月16日
YugantM/hvtrackerAI Agent Trust Registry — independent, evidence-based trust scores for 300+ open-source AI agents. Runtime-trust calibrated (MCP, dependencies, provenance drift), with side-by-side comparison and embeddable live badges. Ranked by verifiable signals, not hype.
HTML★ 52026年7月26日

haqaliz/belayThe agent harness: sandbox any agent, verify each step by replaying it against real state, and keep a deterministic trace.
Python★ 0↓ 2,022/月2026年8月20日