AgentDish directory

security

Accepted listings with this tag.

Listing Category Score Trend Checked
#638 ↓ -3
Security Cards

Open-source security guidance for specific libraries and versions, aimed at developers and coding agents. The repo includes local setup steps, a web site, and an installable skill for agent workflows.

Developer Tool / Security / AI Coding Assistant 85 ↓ -3 28 days ago Details
#649 ↓ -3
Numbat

Open-source endpoint visibility and response for AI agents, with local detection, optional pre-action blocking, and forensic reconstruction.

Security / Endpoint Security 85 ↓ -3 33 days ago Details
#670 ↓ -3
Toolport

Local-first MCP gateway that lets multiple AI clients share one server setup, with lazy tool discovery to reduce token usage and built-in tool integrity and quarantine controls.

Developer Tools / MCP / AI Infrastructure 85 ↓ -3 47 days ago Details
#687 ↓ -3
Exfault

Exfault is an autonomous Android security testing tool that uses AI agents, static analysis, dynamic analysis, authenticated workflows, and cloud emulators to produce reproducible findings and reports.

Security / Mobile Security 85 ↓ -3 64 days ago Details
#717 ↓ -3
HoneyLabs

A honeypot telemetry and threat intelligence service with searchable IP lookups, recent scanner data, and an MCP/JSON-RPC API for agents and developers.

Security / Threat Intelligence 85 ↓ -3 106 days ago Details
#735 ↓ -6
Weir

Weir is a CI gate for AI agents that reads OpenTelemetry traces and fails builds when sensitive data reaches forbidden sinks. It includes a gauge for trace coverage, taint tracking, HTML reports, and rule-based scans for agent workflows.

Developer Tools / AI Testing 84 ↓ -6 3 days ago Details
#767 ↓ -6
aileaks

CLI and GitHub Action that scans repos, logs, and CI artifacts for leaked LLM reasoning-trace blocks from Anthropic, OpenAI, and Google.

Developer Tools / Security 84 ↓ -6 20 days ago Details
#777 ↓ -6
Kotro

Kotro is a local control plane for coding agents that governs MCP tool actions and LLM traffic with one binary. The page shows install options, supported clients, dashboard access, and concrete controls like schema pinning, redaction, cache, budget, and circuit breaker behavior.

Developer Tools / Code Assistant 84 ↓ -6 27 days ago Details
#783 ↓ -6
Clawx

An open-source agent-driven package manager for versioned, checksummed, approval-gated tasks run through Claude Code, Codex, Gemini CLI, OpenCode, or Antigravity.

Developer Tools / AI Agent Infrastructure 84 ↓ -6 28 days ago Details
#800 ↓ -6
Hotcell

Hotcell is a self-hostable sandbox SDK for AI agents that runs isolated sandboxes on local hardware or servers. The page shows setup, CLI commands, key handling, egress control, and support for containers or microVMs.

Developer Tools / AI Developer Tooling 84 ↓ -6 35 days ago Details
#838 ↓ -6
B.I.O.M.A. Framework

A local Rust-plus-Python middleware layer for LLM apps that claims to reduce token usage and add in-process security checks before prompts are sent to a provider.

Developer Tool / LLM middleware 84 ↓ -6 46 days ago Details
#915 ↓ -6
agent-vault-proxy

A loopback HTTPS proxy that swaps placeholders for real API keys at request time, keeping secrets out of the agent process. It uses Bitwarden Secrets Manager and supports scoped bindings for hosts, methods, and paths.

Developer Tool / Security 84 ↓ -6 81 days ago Details
#923 ↓ -6
AgentTrust ID

Runtime authorization platform for AI agents with open-source SDKs in Python, TypeScript, Go, Java, and Rust. The page says the hosted service is in production, supports per-action checks, scoped delegation, revocable tokens, and a shared authorization model across MCP tools, agent-to-agent calls, and direct API integr

AI Developer Tool / Agent Security / Authorization 84 ↓ -6 85 days ago Details
#925 ↓ -6
Sandfence

A minimal native macOS sandbox for running Claude Code or Codex with OS-enforced limits on what the agent can touch.

Developer Tools / Security 84 ↓ -6 87 days ago Details

An open-source reference implementation for autonomous vulnerability discovery and remediation with Claude. It includes Claude Code skills for threat modeling, scanning, triage, patching, plus a harness for running a recon → find → verify → report → patch pipeline.

Security / AI Security 84 ↓ -6 88 days ago Details
#941 ↓ -6
mcpguard

Open-source security scanner and firewall for MCP servers. It scans configs for common MCP risks, enforces runtime policies on tool calls, and produces audit logs, with CLI commands, policy examples, and a programmatic API.

Developer Tools / Security 84 ↓ -6 93 days ago Details
#953 ↓ -6
terminal-guardian-mcp

A secure Model Context Protocol server that gives AI assistants controlled terminal access with risk analysis, sandboxing, logging, filesystem protection, and optional Docker and Git features.

Developer Tools / MCP Servers 84 ↓ -6 101 days ago Details
#972 ↓ -6
AI Action Path Lab

An interactive lab for tracing how AI-assisted engineering workflows can reach repos, CI/CD, credentials, tools, approvals, and proof trails.

Productivity / Workflow Automation 84 ↓ -6 110 days ago Details
#996 ↑ +149
Faramesh

Runtime governance and containment for AI agents. Faramesh sits between an agent and its tools to enforce policy checks, approval steps, credential isolation, and tamper-evident audit logs before risky actions execute.

Developer Tools / AI Governance / Agent Security 84 ↑ +149 118 days ago Details

A security product for Claude Code that reviews application architecture inside the IDE via MCP, with contextual assessments, prioritized mitigations, and continuous re-checks as the codebase changes.

AI Security / AI Application Security 84 ↑ +321 118 days ago Details
#1033 ↓ -3
Sentrint

Sentrint is a security scanner for apps built with LLM platforms like Bolt, Cursor, and v0. It scans repos for secrets, access rules, vulnerable dependencies, and risky code paths, then returns plain-English findings and a copy-paste fix prompt.

Security / Code Security 83 ↓ -3 12 days ago Details
#1035 ↓ -3
agent-guard

A lightweight shell-based guard that blocks destructive commands before an AI coding agent can run them. It targets risky actions like git reset --hard, rm -rf, force-pushes, and destructive cloud/database commands, with local regex rules and a test script.

Developer Tools / AI Agent Safety 83 ↓ -3 16 days ago Details
#1047 ↓ -3
mcpvessel

A CLI for running untrusted MCP servers in sandboxed containers with deny-by-default egress, traffic watching, and host approval workflows. It can also compose servers into agents and expose them over OCI registries.

Developer Tools / Security / Sandboxing 83 ↓ -3 27 days ago Details
#1073 ↓ -3
mcp-audit

A harness that runs MCP servers in a disposable Linux sandbox and logs their real startup behavior, including file access and outbound network connections.

Developer Tools / AI Tooling 83 ↓ -3 54 days ago Details