Python★ 2,4232026年8月13日
arcjet/arcjet-jsArcjet JavaScript (JS) / TypeScript SDK. Stop bots and automated attacks from burning your AI budget, leaking data, or misusing tools with Arcjet's AI security building blocks.
TypeScript★ 675↓ 719K/月2026年7月19日
PyPI · crates.io · npm93卓越健康指数

hashgraph-online/hol-guardOpen-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/月2026年9月5日
Python★ 155↓ 2,902/月2026年8月25日
NuGuardAI/nuguardopensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Python★ 10↓ 4,954/月2026年7月18日

asamassekou10/ship-safeCLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/月2026年9月6日
Typst · Python★ 8122026年7月28日

issdandavis/SCBE-AETHERMOOREGeometric AI governance and evaluation framework with a 14-layer security pipeline, semantic projection, and reproducible benchmark lanes.
Python · TypeScript★ 6↓ 4,607/月2026年8月26日

peg/rampartOpen-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.
Go★ 832026年9月6日
Agent-Threat-Rule/agent-threat-rulesOpen detection standard -- like Sigma, but for AI agents. 425 rules, shipped in Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H. 97.1% recall on NVIDIA garak. NIST OSCAL Path 1.
TypeScript★ 314↓ 9,370/月2026年7月16日
lua-ai-global/governanceZero-dependency TypeScript SDK for AI agent governance: policy enforcement, injection detection, tamper-evident audit, and standards mapping (EU AI Act, OWASP, NIST, ISO 42001)
TypeScript★ 25↓ 3,545/月2026年7月26日

Synapsor/Synapsor-RunnerLet AI agents query and update Postgres/MySQL without raw SQL, unrestricted schema access, or database credentials in the model; writes stay reviewed.
TypeScript · JavaScript★ 2↓ 5,822/月2026年8月22日
bookedsolidtech/reaZero-trust governance layer for Claude Code. Policy-enforced MCP gateway with autonomy controls, middleware chain, audit log, HALT kill-switch, and prompt-injection defense.
TypeScript · Shell★ 0↓ 1,950/月2026年7月27日
gautamvarmadatla/mcpsafetywardenMCP servers expose tools with no information about what they actually do at runtime. mcpsafetywarden sits between your agent and any MCP server, profiling tool behavior, blocking destructive calls, and running active security audits before you trust them in a workflow.
Python★ 9↓ 2,923/月2026年8月1日

panguard-ai/panguard-aiOpen-source security platform for AI agents -- audits skills before install, monitors 24/7, shares threat intelligence across all users. | AI Agent 開源安全平台 -- 安裝前審計 skill、24/7 即時監控、社群共享威脅情報。
TypeScript★ 63↓ 1,214/月2026年9月5日
JavaScript · Python★ 10↓ 126.9K/月2026年9月5日

fissible/verdictDeterministic authorization boundary for laravel/ai agents — models propose, applications authorize.
PHP★ 2↓ 2,275/月2026年8月30日
Go · Python★ 122026年7月23日
PrismorSec/prismorRuntime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/月2026年7月19日

vaquarkhan/MCP-BastionMCP-Bastion: The Zero-Infrastructure Runtime Middleware ,Enterprise-Grade Security Middleware for the Model Context Protocol (MCP)
Python★ 4↓ 3,959/月2026年8月16日

Drakon-Systems-Ltd/ShieldCortex🧠🛡️ Complete memory & security for AI agents. Persistent storage, semantic search, prompt injection firewall, audit trail. One package.
TypeScript★ 25↓ 14.6K/月2026年8月22日
Python★ 45↓ 1,793/月2026年7月17日
goklab/guardvibeSecurity infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/月2026年7月17日
secure-vector/ai-threat-monitorSecurity & Observability for AI Agents — audit every tool call, enforce allow/block policies, catch prompt injection and data leaks. Local-first; works with Claude Code, Codex, Copilot CLI, OpenClaw, LangChain, and all major LLM APIs.
Python · JavaScript★ 132026年7月16日

tiagosilva07/zyrax-guardAudit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 22026年8月28日
famclaw/honeybadgerSecurity scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 32026年7月17日

kahramanemir/VallumSecurity boundary CLI proxy between AI coding agents and your shell — redacts secrets, neutralizes prompt injection, wraps untrusted terminal output, and audits every command. Single Rust binary.
Rust★ 5↓ 159/月2026年9月6日
Python★ 5↓ 2,657/月2026年8月2日
Python★ 13↓ 373/月2026年7月19日
TypeScript★ 99↓ 226.3K/月2026年7月29日