AgentDish directory
security
Accepted listings with this tag.
| Listing | Category | Score | Trend | Checked | |
|---|---|---|---|---|---|
|
#638
↓ -3
Security Cards
Open-source security guidance for specific libraries and versions, aimed at developers and coding agents. The repo includes local setup steps, a web site, and an installable skill for agent workflows. |
Developer Tool / Security / AI Coding Assistant | 85 | ↓ -3 | 28 days ago | Details |
|
#649
↓ -3
Numbat
Open-source endpoint visibility and response for AI agents, with local detection, optional pre-action blocking, and forensic reconstruction. |
Security / Endpoint Security | 85 | ↓ -3 | 33 days ago | Details |
|
#670
↓ -3
Toolport
Local-first MCP gateway that lets multiple AI clients share one server setup, with lazy tool discovery to reduce token usage and built-in tool integrity and quarantine controls. |
Developer Tools / MCP / AI Infrastructure | 85 | ↓ -3 | 47 days ago | Details |
|
#687
↓ -3
Exfault
Exfault is an autonomous Android security testing tool that uses AI agents, static analysis, dynamic analysis, authenticated workflows, and cloud emulators to produce reproducible findings and reports. |
Security / Mobile Security | 85 | ↓ -3 | 64 days ago | Details |
|
#717
↓ -3
HoneyLabs
A honeypot telemetry and threat intelligence service with searchable IP lookups, recent scanner data, and an MCP/JSON-RPC API for agents and developers. |
Security / Threat Intelligence | 85 | ↓ -3 | 106 days ago | Details |
|
#735
↓ -6
Weir
Weir is a CI gate for AI agents that reads OpenTelemetry traces and fails builds when sensitive data reaches forbidden sinks. It includes a gauge for trace coverage, taint tracking, HTML reports, and rule-based scans for agent workflows. |
Developer Tools / AI Testing | 84 | ↓ -6 | 3 days ago | Details |
|
#767
↓ -6
aileaks
CLI and GitHub Action that scans repos, logs, and CI artifacts for leaked LLM reasoning-trace blocks from Anthropic, OpenAI, and Google. |
Developer Tools / Security | 84 | ↓ -6 | 20 days ago | Details |
|
#777
↓ -6
Kotro
Kotro is a local control plane for coding agents that governs MCP tool actions and LLM traffic with one binary. The page shows install options, supported clients, dashboard access, and concrete controls like schema pinning, redaction, cache, budget, and circuit breaker behavior. |
Developer Tools / Code Assistant | 84 | ↓ -6 | 27 days ago | Details |
|
#783
↓ -6
Clawx
An open-source agent-driven package manager for versioned, checksummed, approval-gated tasks run through Claude Code, Codex, Gemini CLI, OpenCode, or Antigravity. |
Developer Tools / AI Agent Infrastructure | 84 | ↓ -6 | 28 days ago | Details |
|
#800
↓ -6
Hotcell
Hotcell is a self-hostable sandbox SDK for AI agents that runs isolated sandboxes on local hardware or servers. The page shows setup, CLI commands, key handling, egress control, and support for containers or microVMs. |
Developer Tools / AI Developer Tooling | 84 | ↓ -6 | 35 days ago | Details |
|
#838
↓ -6
B.I.O.M.A. Framework
A local Rust-plus-Python middleware layer for LLM apps that claims to reduce token usage and add in-process security checks before prompts are sent to a provider. |
Developer Tool / LLM middleware | 84 | ↓ -6 | 46 days ago | Details |
|
#915
↓ -6
agent-vault-proxy
A loopback HTTPS proxy that swaps placeholders for real API keys at request time, keeping secrets out of the agent process. It uses Bitwarden Secrets Manager and supports scoped bindings for hosts, methods, and paths. |
Developer Tool / Security | 84 | ↓ -6 | 81 days ago | Details |
|
#923
↓ -6
AgentTrust ID
Runtime authorization platform for AI agents with open-source SDKs in Python, TypeScript, Go, Java, and Rust. The page says the hosted service is in production, supports per-action checks, scoped delegation, revocable tokens, and a shared authorization model across MCP tools, agent-to-agent calls, and direct API integr |
AI Developer Tool / Agent Security / Authorization | 84 | ↓ -6 | 85 days ago | Details |
|
#925
↓ -6
Sandfence
A minimal native macOS sandbox for running Claude Code or Codex with OS-enforced limits on what the agent can touch. |
Developer Tools / Security | 84 | ↓ -6 | 87 days ago | Details |
|
#929
↓ -6
Defending Code Reference Harness
An open-source reference implementation for autonomous vulnerability discovery and remediation with Claude. It includes Claude Code skills for threat modeling, scanning, triage, patching, plus a harness for running a recon → find → verify → report → patch pipeline. |
Security / AI Security | 84 | ↓ -6 | 88 days ago | Details |
|
#941
↓ -6
mcpguard
Open-source security scanner and firewall for MCP servers. It scans configs for common MCP risks, enforces runtime policies on tool calls, and produces audit logs, with CLI commands, policy examples, and a programmatic API. |
Developer Tools / Security | 84 | ↓ -6 | 93 days ago | Details |
|
#953
↓ -6
terminal-guardian-mcp
A secure Model Context Protocol server that gives AI assistants controlled terminal access with risk analysis, sandboxing, logging, filesystem protection, and optional Docker and Git features. |
Developer Tools / MCP Servers | 84 | ↓ -6 | 101 days ago | Details |
|
#972
↓ -6
AI Action Path Lab
An interactive lab for tracing how AI-assisted engineering workflows can reach repos, CI/CD, credentials, tools, approvals, and proof trails. |
Productivity / Workflow Automation | 84 | ↓ -6 | 110 days ago | Details |
|
#996
↑ +149
Faramesh
Runtime governance and containment for AI agents. Faramesh sits between an agent and its tools to enforce policy checks, approval steps, credential isolation, and tamper-evident audit logs before risky actions execute. |
Developer Tools / AI Governance / Agent Security | 84 | ↑ +149 | 118 days ago | Details |
|
#1011
↑ +321
Trent AI Claude Code Security
A security product for Claude Code that reviews application architecture inside the IDE via MCP, with contextual assessments, prioritized mitigations, and continuous re-checks as the codebase changes. |
AI Security / AI Application Security | 84 | ↑ +321 | 118 days ago | Details |
|
#1033
↓ -3
Sentrint
Sentrint is a security scanner for apps built with LLM platforms like Bolt, Cursor, and v0. It scans repos for secrets, access rules, vulnerable dependencies, and risky code paths, then returns plain-English findings and a copy-paste fix prompt. |
Security / Code Security | 83 | ↓ -3 | 12 days ago | Details |
|
#1035
↓ -3
agent-guard
A lightweight shell-based guard that blocks destructive commands before an AI coding agent can run them. It targets risky actions like git reset --hard, rm -rf, force-pushes, and destructive cloud/database commands, with local regex rules and a test script. |
Developer Tools / AI Agent Safety | 83 | ↓ -3 | 16 days ago | Details |
|
#1047
↓ -3
mcpvessel
A CLI for running untrusted MCP servers in sandboxed containers with deny-by-default egress, traffic watching, and host approval workflows. It can also compose servers into agents and expose them over OCI registries. |
Developer Tools / Security / Sandboxing | 83 | ↓ -3 | 27 days ago | Details |
|
#1073
↓ -3
mcp-audit
A harness that runs MCP servers in a disposable Linux sandbox and logs their real startup behavior, including file access and outbound network connections. |
Developer Tools / AI Tooling | 83 | ↓ -3 | 54 days ago | Details |