
NVIDIA-NeMo/GuardrailsNeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.
Python★ 6,930↓ 394.8K/月2026年8月12日

data-privacy-stack/presidioAn open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports NLP, pattern matching, and customizable pipelines.
Python★ 10.7K↓ 12.1M/月2026年8月27日

maximhq/bifrostFastest enterprise AI gateway (50x faster than LiteLLM) with adaptive load balancer, cluster mode, guardrails, 1000+ models support & <100 µs overhead at 5k RPS.
Go · TypeScript★ 7,6082026年8月28日
Go · crates.io · Maven +296卓越健康指数
Rust · TypeScript★ 9,0832026年8月28日

akto-api-security/aktoAkto is the fastest growing AI Security platform for your teams to secure AI agents, MCPs, LLMs, Agent skills, Gen AI apps in your organization.
Java · JavaScript★ 1,5122026年9月5日
Python★ 155↓ 2,902/月2026年8月25日
datafog/datafog-pythonOffline PII firewall for AI agents and LLM apps: fast local detection and redaction, Claude Code hook, LiteLLM guardrail. Zero network calls, one dependency.
Python★ 67↓ 34K/月2026年7月16日
ferro-labs/ai-gatewayUnified AI Gateway for 30+ LLMs (OpenAI, Anthropic, Bedrock, Azure etc) with Caching, Guardrails, A/B test & cost controls. Go-native Fastest & Scalable AI Gateway LiteLLM & Kong AI Gateway alternative.
Go★ 1832026年7月17日

ZaxbyHub/opencode-swarm Architect-centric agentic swarm plugin for OpenCode. Hub-and-spoke orchestration with SME consultation, code generation, and QA review.
TypeScript★ 451↓ 18.5K/月2026年8月22日
TypeScript★ 4↓ 4,137/月2026年7月18日

CoWork-OS/CoWork-OSLocal-first personal agentic OS and everything app for coding, knowledge work, web design, automations, and artifacts.
TypeScript★ 418↓ 704/月2026年8月8日
lua-ai-global/governanceZero-dependency TypeScript SDK for AI agent governance: policy enforcement, injection detection, tamper-evident audit, and standards mapping (EU AI Act, OWASP, NIST, ISO 42001)
TypeScript★ 25↓ 3,545/月2026年7月26日
IgorGanapolsky/ThumbGateThumbGate Pre-Action Checks derive rules from repeated failures, flag risky tool calls, hard-block detected secret leaks, and block matches in strict mode.
JavaScript · HTML★ 24↓ 4,611/月2026年7月19日

cendorhq/cendor-libs-jsProduction plumbing for LLM apps in TypeScript: context, cost, testing & governance primitives. Python-interoperable.
TypeScript★ 0↓ 12.9K/月2026年8月29日
Python★ 172026年7月26日
bookedsolidtech/reaZero-trust governance layer for Claude Code. Policy-enforced MCP gateway with autonomy controls, middleware chain, audit log, HALT kill-switch, and prompt-injection defense.
TypeScript · Shell★ 0↓ 1,950/月2026年7月27日
hedypamungkas/koboi-agentSelf-hostable AI agents you can actually leave running — durable crash-resume, governed autonomy, seccomp sandbox, offline-replayable workflows, CI-native eval. Async-Python, YAML-config, multi-provider (OpenAI/Anthropic/Cloudflare), MIT.
Python★ 1↓ 4,014/月2026年7月19日
TypeScript★ 257↓ 12.4K/月2026年7月27日
Python★ 6↓ 2,560/月2026年9月5日
philpaz/recusalDeterministic governance for Claude and MCP tool calls. Pin approved capabilities, detect drift, and refuse unsafe or unapproved actions before execution. No model in the decision path.
Python★ 3↓ 2,854/月2026年7月27日
PrismorSec/prismorRuntime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/月2026年7月19日

cendorhq/cendor-libsProduction plumbing for LLM apps: context, cost, testing & governance — composable, framework-agnostic Python libraries.
Python★ 0↓ 5,524/月2026年8月29日
TypeScript★ 87↓ 52.6K/月2026年7月23日
crp4222/PrivAiTeDrop-in self-hosted LLM proxy that reversibly redacts PII before OpenAI, ChatGPT and Ollama calls, including inside tool-call arguments and multimodal content. OpenAI-compatible, zero telemetry.
Python★ 202026年7月19日

kahramanemir/VallumSecurity boundary CLI proxy between AI coding agents and your shell — redacts secrets, neutralizes prompt injection, wraps untrusted terminal output, and audits every command. Single Rust binary.
Rust★ 5↓ 159/月2026年9月6日
lelu-ai/leluOpen source authorization engine for AI agents. Confidence-aware gating · Human-in-the-loop review · Policy-as-code · Full audit trail
TypeScript · Go★ 432026年7月16日
Python★ 13↓ 373/月2026年7月19日

abhishektiwari/dogwood-pyPython SDK and PyO3 binding for the Dogwood temporal policy language. Batteries for Strand Agents included.
Python★ 0↓ 3,824/月2026年8月15日
microvn/specpipeSpec-first development toolkit for agentic AI coding agents — skills + guardrails for Claude Code, Codex, Cursor, Antigravity, and more.
JavaScript · Shell · HTML★ 2↓ 2,543/月2026年7月22日
Python★ 0↓ 3,656/月2026年8月1日