Security middleware
-
agent-egress-bench
Provide an open test corpus to assess and improve AI agent egress security through validated cases and automated workflows.
-
ailang-world
An AI-native semantic operating environment: a local-first, immutable typed world graph whose transaction language is AILANG. Agents propose, deterministic verification commits, humans govern.
-
atlas.compass
🔒 Securely manage passwords locally in the terminal with AES-256 encryption and zero-knowledge master key control using atlas.compass.
-
atlas.compass
A secure, local-first terminal password manager. Zero-knowledge AES-256-GCM encryption, Argon2id key derivation, and a high-visibility TUI. Part of the Atlas Suite.
-
batesian
Active security scanner for A2A and MCP servers
-
Casbin
Authorization library supporting access-control models like ACL, RBAC, and ABAC.
-
cerebro
Security and compliance superpowers for coding agents.
-
Charon
A lightweight, user-friendly web interface for managing Caddy as a reverse proxy. It simplifies SSL management and host routing for self-hosters who want the power of Caddy without the manual configuration.
-
clrk
Cognitive Loop Runtime for Kubernetes
-
depmesh-ai
Vet an open-source dependency before you (or your coding agent) adopt it.
-
draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
-
enclave
Sandbox for running AI coding agents autonomously: isolated, network-restricted, host-safe
-
gh-actions-lock
A gh CLI extension that generates and verifies the GitHub Actions dependency lockfile, pinning every action your workflows use to an exact commit.
-
ghir
ghir is a CLI making past GitHub Releases immutable
-
hideout
Run AI agents and untrusted CLIs in a local VM without losing host-native workflows.
-
hostveil
A single-binary guided hardening tool for self-hosted Linux servers — scan, score, and fix with preview, backup and one-command rollback
-
ironclaw
Security-first, self-hosted AI agents - isolation you can prove, not just promise.
-
klanker-maker
klanker-maker ('km') is an AWS policy-driven sandbox platform for safer agentic AI. Define execution environments as declarative YAML profiles, compile them into real AWS infrastructure (EC2/ECS) using Go CLI . 💚
-
lopper
measure dependency waste and attack surface before it ships
-
meshmcp
The identity-native control plane for agent↔tool (MCP) traffic. Every MCP server runs on a private WireGuard mesh — zero open ports — behind an agent firewall: tamper-evident signed audit, policy learned from behavior, identity-gated secrets, and audited cross-org federation. One static Go binary.
-
nenya
A lightweight, highly secure AI API Gateway/Proxy written in Go. Acts as transparent middleware between local AI coding clients (OpenCode/Pi/Cursor) and upstream LLM providers (Gemini, DeepSeek, Zhipu z.ai).
-
nowifi
No WiFi? Now WiFi. One command. 27 techniques. Bypass any captive portal.
-
sbomhub
日本市場向けオープンソースSBOM管理ダッシュボード / Open-source SBOM management dashboard with NVD/JVN vulnerability correlation, Japanese UI, and METI guidelines compliance
Security Go -
sigil
Self-hosted favicon resolver with an SSRF-hardened fetch boundary. Resolves a domain's real favicon server-side so lookups never leak to a third party.
Security Go -
snitch
Single static-binary recon orchestrator in Go: chains subfinder, httpx, nmap, nuclei, ffuf, katana + injection testing (dalfox/crlfuzz/sqlmap), with dedup, diff-based webhook alerts, an interactive TUI and JSON/CSV/SARIF export.
-
sockguard
Docker socket proxy. Filter API requests by method and path with default-deny posture, structured audit logging, and Tecnativa drop-in compatibility.
Security Go -
themis
Audits a Debian or Ubuntu host, fixes what it finds, and keeps it fixed: check, plan, apply, rollback. Written in Go.
-
Unpinched
Detect PinchTab deployments and browser bridge artifacts with a fast, point-in-time scanner for security and forensic analysis.
-
xQuakShell
Portable, secure remote-access platform extensible via sandboxed out-of-process plugins. Encrypted vault, strict host-key verification, capability-gated IPC. Built with Go + Wails.