AgentDish directory
prompt-injection
Accepted listings with this tag.
| Listing | Category | Score | Trend | Checked | |
|---|---|---|---|---|---|
|
#8
↑ +10
Snyk Agent Scan
Open-source security scanner for AI agents, MCP servers, and agent skills. It auto-discovers installed agent components and checks them for prompt injection, tool poisoning, secrets, malware payloads, and related risks. |
Security / Agent Security | 92 | ↑ +10 | 117 days ago | Details |
|
#17
↓ -3
OWASP Agent Memory Guard
An OWASP incubator project that protects AI agent memory from prompt injection, secret leakage, and tampering. It includes a Python library, policy-based controls, benchmarks, and integrations for agent frameworks like LangChain and AutoGen. |
Developer Tools / AI Security | 91 | ↓ -3 | 92 days ago | Details |
|
#42
↓ -2
PromptTrace
Free hands-on labs for prompt injection and LLM security training, with real models, a context trace view of assembled prompts, and a multi-level Gauntlet challenge. |
AI Security / Prompt Injection Training | 90 | ↓ -2 | 34 days ago | Details |
|
#214
↓ -3
Belay
Belay is an open-source, local-first security layer for AI coding agents. It blocks dangerous commands, secret leaks, prompt injection, and risky MCP tool calls, with human approval flows and support for multiple agents. |
Security / AI Agent Security | 88 | ↓ -3 | 35 days ago | Details |
|
#539
↑ +2
Lelu
Open-source authorization engine for AI agents that adds confidence-based gating, human review, policy-as-code, and audit logging. The repo shows quickstart code, local demo steps, SDK installs, and self-hosting options. |
Developer Tool / AI Authorization / Security | 86 | ↑ +2 | 72 days ago | Details |
|
#542
↑ +2
NILScript
NILScript is an open standard and CLI toolkit for letting AI agents act on real systems through a gated propose → approve → commit → rollback flow. The page shows a live playground, quickstart commands, and benchmark claims around unauthorized writes. |
Developer Tools / Code Assistant | 86 | ↑ +2 | 74 days ago | Details |
|
#655
↓ -3
LLM Red Team Lab
A hands-on kit for authorized red teaming of locally run LLMs, with jailbreak techniques, prompt-injection scenarios, streaming attack visualization, and support for OpenAI-compatible local model servers. |
Security / AI Red Teaming | 85 | ↓ -3 | 35 days ago | Details |
|
#656
↓ -3
ModelFuzz
Open-source runtime guardrails for AI agents that scans for prompt-injection weaknesses and blocks unsafe tool calls at execution time with a decorator. |
Developer Tools / Code Assistant | 85 | ↓ -3 | 35 days ago | Details |
|
#785
↓ -6
ModelFuzz
Open-source runtime guardrails for AI agents that intercept unsafe tool calls before they execute, aiming to block prompt-injection-driven exfiltration and other policy violations. |
Developer Tools / AI Safety | 84 | ↓ -6 | 27 days ago | Details |
|
#818
↓ -6
Sunglasses
Open-source input scanner for AI agents that strips hidden instructions and scans text, files, images, PDFs, QR codes, audio, and video before they reach an agent. |
Security / AI Security / Prompt Injection Defense | 84 | ↓ -6 | 39 days ago | Details |
|
#845
↓ -6
ClaySeal Arena
A prompt-injection capture-the-flag arena for testing how AI agents behave under attack. Users can play challenges, create guarded agents, add optional guards and sandboxed tools, and track scores on a leaderboard. |
Developer Tools / Code Assistant | 84 | ↓ -6 | 46 days ago | Details |
|
#876
↓ -6
Declaw Arena
An interactive CTF-style challenge where users try to break or exfiltrate data from sandboxed AI agents running in Declaw’s isolated runtime. |
Security / AI Agent Security | 84 | ↓ -6 | 59 days ago | Details |
|
#887
↓ -6
Lelu
Open-source authorization engine for AI agents that gates actions by confidence, policy, and human review, with prompt-injection detection and full audit logging. |
Developer Tools / AI Agent Security | 84 | ↓ -6 | 67 days ago | Details |
|
A blog post describing Annex, a local-AI security tool that encrypts selected files during agent sessions to keep sensitive data away from local AI tools. The post explains the threat model, encryption flow, and the stack used to build it. |
Security / Local AI Security | 82 | ↓ -2 | 42 days ago | Details |
|
#1281
↓ -2
Blue41: Securing a financial AI assistant
A Blue41 case study on how a banking AI assistant could be abused through indirect prompt injection, and what mitigation layers help reduce the risk. |
Security / AI Security | 82 | ↓ -2 | 82 days ago | Details |
|
#1285
↓ -2
Jo
Jo is a secure programming language designed to help catch prompt injection and other unsafe behavior at compile time by enforcing explicit capability boundaries. The repository shows the language’s security model, code examples, installation flow, and current project status. |
Developer Tools / AI Security | 82 | ↓ -2 | 87 days ago | Details |
|
#1652
→ 0
Prompt Injection as Role Confusion
An ICML 2026 research project page arguing that prompt injection comes from how LLMs misread roles, with an extended writeup, examples, and links to the paper, code, arXiv, and BibTeX. |
Research / AI Safety | 77 | → 0 | 69 days ago | Details |
|
A Noma Security research post detailing a prompt-injection flaw in GitHub Agentic Workflows, with attack flow, proof-of-concept evidence, and security recommendations. |
Security / AI Security Research | 76 | ↓ -1 | 54 days ago | Details |
|
#1724
→ 0
VAIBot
VAIBot is an AI governance product focused on agent security. This page explains its prompt-injection threat model and positions the product as a circuit breaker that gates tool calls and other egress actions before they execute. |
AI Governance / Agent Security | 75 | → 0 | 52 days ago | Details |
|
#1792
↓ -1
The Cat Is Under Mayonnaise
An open-source experiment that adds a small zero-initialized overlay layer to a frozen GPT-2 so its behavior can be adjusted at inference time without retraining the base model. |
AI Developer Tool / Model Adaptation / Adapters | 74 | ↓ -1 | 117 days ago | Details |