AgentDish directory
Security AI Tools
Accepted listings in this category.
| Listing | Category | Score | Trend | Checked | |
|---|---|---|---|---|---|
|
#8
↑ +10
Snyk Agent Scan
Open-source security scanner for AI agents, MCP servers, and agent skills. It auto-discovers installed agent components and checks them for prompt injection, tool poisoning, secrets, malware payloads, and related risks. |
Security / Agent Security | 92 | ↑ +10 | 117 days ago | Details |
|
#48
↓ -2
Xalgorix
Self-hosted AI security testing platform for authorized pentesting and bug bounty workflows, with a local web UI, live agent telemetry, verified findings, and branded PDF reports. |
Security / Penetration Testing | 90 | ↓ -2 | 56 days ago | Details |
|
#140
→ 0
Bright Security Agent
GitHub Marketplace app from NeuraLegion that scans apps and APIs for vulnerabilities, proposes fixes, and validates remediations inside GitHub workflows. |
Security / Application Security | 89 | → 0 | 85 days ago | Details |
|
#214
↓ -3
Belay
Belay is an open-source, local-first security layer for AI coding agents. It blocks dangerous commands, secret leaks, prompt injection, and risky MCP tool calls, with human approval flows and support for multiple agents. |
Security / AI Agent Security | 88 | ↓ -3 | 35 days ago | Details |
|
#349
↓ -4
OneCLI
Open-source credential gateway for AI agents that injects service credentials without exposing the real keys to the agent. Includes a vault, access tokens, host/path matching, and local quick-start instructions. |
Security / Secrets Management | 87 | ↓ -4 | 38 days ago | Details |
|
#527
↑ +2
Bulwark
Kernel-level read gate for AI coding agents that blocks protected file reads before bytes reach the agent, with Linux fanotify and macOS Endpoint Security support. |
Security / Developer Security Tool | 86 | ↑ +2 | 62 days ago | Details |
|
#649
↓ -3
Numbat
Open-source endpoint visibility and response for AI agents, with local detection, optional pre-action blocking, and forensic reconstruction. |
Security / Endpoint Security | 85 | ↓ -3 | 32 days ago | Details |
|
#655
↓ -3
LLM Red Team Lab
A hands-on kit for authorized red teaming of locally run LLMs, with jailbreak techniques, prompt-injection scenarios, streaming attack visualization, and support for OpenAI-compatible local model servers. |
Security / AI Red Teaming | 85 | ↓ -3 | 35 days ago | Details |
|
#687
↓ -3
Exfault
Exfault is an autonomous Android security testing tool that uses AI agents, static analysis, dynamic analysis, authenticated workflows, and cloud emulators to produce reproducible findings and reports. |
Security / Mobile Security | 85 | ↓ -3 | 63 days ago | Details |
|
#717
↓ -3
HoneyLabs
A honeypot telemetry and threat intelligence service with searchable IP lookups, recent scanner data, and an MCP/JSON-RPC API for agents and developers. |
Security / Threat Intelligence | 85 | ↓ -3 | 105 days ago | Details |
|
#803
↓ -6
ASL V6
Open-source security research tool for auditing Python AI agents and codebases with AST analysis and Docker-based runtime verification. |
Security / AI Security / Red Teaming | 84 | ↓ -6 | 35 days ago | Details |
|
#818
↓ -6
Sunglasses
Open-source input scanner for AI agents that strips hidden instructions and scans text, files, images, PDFs, QR codes, audio, and video before they reach an agent. |
Security / AI Security / Prompt Injection Defense | 84 | ↓ -6 | 39 days ago | Details |
|
#876
↓ -6
Declaw Arena
An interactive CTF-style challenge where users try to break or exfiltrate data from sandboxed AI agents running in Declaw’s isolated runtime. |
Security / AI Agent Security | 84 | ↓ -6 | 59 days ago | Details |
|
#929
↓ -6
Defending Code Reference Harness
An open-source reference implementation for autonomous vulnerability discovery and remediation with Claude. It includes Claude Code skills for threat modeling, scanning, triage, patching, plus a harness for running a recon → find → verify → report → patch pipeline. |
Security / AI Security | 84 | ↓ -6 | 87 days ago | Details |
|
#1033
↓ -3
Sentrint
Sentrint is a security scanner for apps built with LLM platforms like Bolt, Cursor, and v0. It scans repos for secrets, access rules, vulnerable dependencies, and risky code paths, then returns plain-English findings and a copy-paste fix prompt. |
Security / Code Security | 83 | ↓ -3 | 11 days ago | Details |
|
#1198
↓ -2
PISIGuard
A browser extension that masks personal and sensitive information before you send messages to AI chat tools, then restores the original values in the reply. |
Security / Privacy | 82 | ↓ -2 | 28 days ago | Details |
|
A blog post describing Annex, a local-AI security tool that encrypts selected files during agent sessions to keep sensitive data away from local AI tools. The post explains the threat model, encryption flow, and the stack used to build it. |
Security / Local AI Security | 82 | ↓ -2 | 42 days ago | Details |
|
#1279
↓ -2
Blue41
Blue41 is an enterprise risk control platform for AI agents. The site says it monitors agent behavior in production, detects prompt-injection-style incidents and unauthorized activity, and helps teams control sensitive workflows and compliance risk. |
Security / AI Security | 82 | ↓ -2 | 81 days ago | Details |
|
#1281
↓ -2
Blue41: Securing a financial AI assistant
A Blue41 case study on how a banking AI assistant could be abused through indirect prompt injection, and what mitigation layers help reduce the risk. |
Security / AI Security | 82 | ↓ -2 | 82 days ago | Details |
|
#1293
↓ -2
ftagent-lite
Open-source Python DDoS traffic monitor that prints live traffic stats to stdout and can output JSON for pipelines and tooling. |
Security / Network Security | 82 | ↓ -2 | 96 days ago | Details |
|
#1547
↑ +6
Mangudai ASM
A public showcase for Mangudai, an external attack surface management and vulnerability management platform for small security teams. The page describes architecture, scan modules, pricing tiers, and the intended SaaS workflow, making it suitable for a directory listing. |
Security / Attack Surface Management | 78 | ↑ +6 | 20 days ago | Details |
|
#1624
↓ -169
Atlas Trust Infrastructure
A metadata-first trust control plane for authorized security workflows, evidence retention, release trust, and business-flow proof. The repository includes role-based docs, quick-start commands, safety boundaries, and release-trust materials. |
Security / Security Operations / Trust Infrastructure | 78 | ↓ -169 | 117 days ago | Details |
|
A Noma Security research post detailing a prompt-injection flaw in GitHub Agentic Workflows, with attack flow, proof-of-concept evidence, and security recommendations. |
Security / AI Security Research | 76 | ↓ -1 | 54 days ago | Details |
|
#1729
→ 0
Giskard
Giskard presents an AI red-teaming and continuous evaluation platform focused on finding hallucinations, security issues, and agent vulnerabilities. The page explains how it compares tools for agent-level testing, regression checks, and guardrail workflows. |
Security / AI Red Teaming | 75 | → 0 | 68 days ago | Details |