AgentDish directory

Security AI Tools

Accepted listings in this category.

Listing Category Score Trend Checked
#8 ↑ +10
Snyk Agent Scan

Open-source security scanner for AI agents, MCP servers, and agent skills. It auto-discovers installed agent components and checks them for prompt injection, tool poisoning, secrets, malware payloads, and related risks.

Security / Agent Security 92 ↑ +10 117 days ago Details
#48 ↓ -2
Xalgorix

Self-hosted AI security testing platform for authorized pentesting and bug bounty workflows, with a local web UI, live agent telemetry, verified findings, and branded PDF reports.

Security / Penetration Testing 90 ↓ -2 56 days ago Details

GitHub Marketplace app from NeuraLegion that scans apps and APIs for vulnerabilities, proposes fixes, and validates remediations inside GitHub workflows.

Security / Application Security 89 → 0 85 days ago Details
#214 ↓ -3
Belay

Belay is an open-source, local-first security layer for AI coding agents. It blocks dangerous commands, secret leaks, prompt injection, and risky MCP tool calls, with human approval flows and support for multiple agents.

Security / AI Agent Security 88 ↓ -3 35 days ago Details
#349 ↓ -4
OneCLI

Open-source credential gateway for AI agents that injects service credentials without exposing the real keys to the agent. Includes a vault, access tokens, host/path matching, and local quick-start instructions.

Security / Secrets Management 87 ↓ -4 38 days ago Details
#527 ↑ +2
Bulwark

Kernel-level read gate for AI coding agents that blocks protected file reads before bytes reach the agent, with Linux fanotify and macOS Endpoint Security support.

Security / Developer Security Tool 86 ↑ +2 62 days ago Details
#649 ↓ -3
Numbat

Open-source endpoint visibility and response for AI agents, with local detection, optional pre-action blocking, and forensic reconstruction.

Security / Endpoint Security 85 ↓ -3 32 days ago Details
#655 ↓ -3
LLM Red Team Lab

A hands-on kit for authorized red teaming of locally run LLMs, with jailbreak techniques, prompt-injection scenarios, streaming attack visualization, and support for OpenAI-compatible local model servers.

Security / AI Red Teaming 85 ↓ -3 35 days ago Details
#687 ↓ -3
Exfault

Exfault is an autonomous Android security testing tool that uses AI agents, static analysis, dynamic analysis, authenticated workflows, and cloud emulators to produce reproducible findings and reports.

Security / Mobile Security 85 ↓ -3 63 days ago Details
#717 ↓ -3
HoneyLabs

A honeypot telemetry and threat intelligence service with searchable IP lookups, recent scanner data, and an MCP/JSON-RPC API for agents and developers.

Security / Threat Intelligence 85 ↓ -3 105 days ago Details
#803 ↓ -6
ASL V6

Open-source security research tool for auditing Python AI agents and codebases with AST analysis and Docker-based runtime verification.

Security / AI Security / Red Teaming 84 ↓ -6 35 days ago Details
#818 ↓ -6
Sunglasses

Open-source input scanner for AI agents that strips hidden instructions and scans text, files, images, PDFs, QR codes, audio, and video before they reach an agent.

Security / AI Security / Prompt Injection Defense 84 ↓ -6 39 days ago Details
#876 ↓ -6
Declaw Arena

An interactive CTF-style challenge where users try to break or exfiltrate data from sandboxed AI agents running in Declaw’s isolated runtime.

Security / AI Agent Security 84 ↓ -6 59 days ago Details

An open-source reference implementation for autonomous vulnerability discovery and remediation with Claude. It includes Claude Code skills for threat modeling, scanning, triage, patching, plus a harness for running a recon → find → verify → report → patch pipeline.

Security / AI Security 84 ↓ -6 87 days ago Details
#1033 ↓ -3
Sentrint

Sentrint is a security scanner for apps built with LLM platforms like Bolt, Cursor, and v0. It scans repos for secrets, access rules, vulnerable dependencies, and risky code paths, then returns plain-English findings and a copy-paste fix prompt.

Security / Code Security 83 ↓ -3 11 days ago Details
#1198 ↓ -2
PISIGuard

A browser extension that masks personal and sensitive information before you send messages to AI chat tools, then restores the original values in the reply.

Security / Privacy 82 ↓ -2 28 days ago Details

A blog post describing Annex, a local-AI security tool that encrypts selected files during agent sessions to keep sensitive data away from local AI tools. The post explains the threat model, encryption flow, and the stack used to build it.

Security / Local AI Security 82 ↓ -2 42 days ago Details
#1279 ↓ -2
Blue41

Blue41 is an enterprise risk control platform for AI agents. The site says it monitors agent behavior in production, detects prompt-injection-style incidents and unauthorized activity, and helps teams control sensitive workflows and compliance risk.

Security / AI Security 82 ↓ -2 81 days ago Details

A Blue41 case study on how a banking AI assistant could be abused through indirect prompt injection, and what mitigation layers help reduce the risk.

Security / AI Security 82 ↓ -2 82 days ago Details
#1293 ↓ -2
ftagent-lite

Open-source Python DDoS traffic monitor that prints live traffic stats to stdout and can output JSON for pipelines and tooling.

Security / Network Security 82 ↓ -2 96 days ago Details
#1547 ↑ +6
Mangudai ASM

A public showcase for Mangudai, an external attack surface management and vulnerability management platform for small security teams. The page describes architecture, scan modules, pricing tiers, and the intended SaaS workflow, making it suitable for a directory listing.

Security / Attack Surface Management 78 ↑ +6 20 days ago Details

A metadata-first trust control plane for authorized security workflows, evidence retention, release trust, and business-flow proof. The repository includes role-based docs, quick-start commands, safety boundaries, and release-trust materials.

Security / Security Operations / Trust Infrastructure 78 ↓ -169 117 days ago Details

A Noma Security research post detailing a prompt-injection flaw in GitHub Agentic Workflows, with attack flow, proof-of-concept evidence, and security recommendations.

Security / AI Security Research 76 ↓ -1 54 days ago Details
#1729 → 0
Giskard

Giskard presents an AI red-teaming and continuous evaluation platform focused on finding hallucinations, security issues, and agent vulnerabilities. The page explains how it compares tools for agent-level testing, regression checks, and guardrail workflows.

Security / AI Red Teaming 75 → 0 68 days ago Details