Security middleware
-
agent-core
Enterprise-grade AI agent engine. Lightweight, secure, MCP-native. Built in Rust.
-
akmon
Tamper-evident evidence and verification layer for AI agents. Verify any agent's session offline with just openssl. No cloud, no lock-in.
-
forgeterm
Monitor AI coding agents in real-time to block unauthorized file access, network connections, and dangerous commands while enforcing system resource limits.
-
franken_node
Trust-native JavaScript/TypeScript runtime platform built on franken_engine with deterministic compatibility, migration autopilot, extension trust controls, and incident replay.
-
gradle-wrapper-validator
A validator for gradle/wrapper jar binaries, intended to be used in CI pipelines.
-
gurgl
Local-first egress hygiene for MCP servers: capture, diff, and allowlist what your AI-agent tools contact on the network.
-
intutic
The open source circuit breaker for AI agents. Real-time security, secret DLP, graph guardrails and loop burn prevention for Claude Code, Cursor, Antigravity, LangGraph, n8n and many more.
-
knife
A reverse engineer's binary Swiss-army knife in Rust: triage, disassembly, function/CFG recovery, crypto-constant + YARA scanning for PE/ELF/Mach-O. Installs as 'knife'.
-
loomdb
An agent-native database. Sessions are branches an agent can fork, merge, and rewind; every write records what it was derived from; and taint-and-recall tells you exactly what a poisoned input contaminated. Built on substrate.
-
nthpartyfinder
Discover Nth-party vendor relationships (3rd, 4th, and deeper) for a domain from public signals — DNS, certificate transparency, trust-center subprocessors, web traffic, and more. A fast, offline-capable GRC Engineering CLI in Rust.
-
numan
The missing package management layer for Nushell. Brings verified registry support, lockfiles, and managed autoloading to plugins, modules, scripts, and completions.
-
Orion
A backend and automation language compiled to bytecode in Rust. One binary, 58 built-in modules, no runtime to install.
-
ovecc
CLI-first, deterministic architecture intelligence. Builds an offline model of your repo to answer impact, cycles, dead code, duplication and security, and enforces your architecture as a contract in CI. No LLM in the loop; usable by coding agents over MCP.
-
pinprick
Pin your GitHub Actions. Prick holes in their supply chain security.
-
remnant
Deterministic npm artifact admission for local and CI supply-chain checks.
-
repopilot
Local-first CLI for reviewing Git changes, security boundaries, and blast radius before merge.
-
security-framework
Security.framework bindings for macOS and iOS
-
security-framework-sys
Apple `Security.framework` low-level FFI bindings
Security Rust -
security-harness-kit
A Rust CLI that scans for secrets, PII, and sensitive data — with native hooks for AI coding assistants to prevent leaking credentials into AI context.
-
server
The self-hosted backend service for the platform, exposing REST and WebSocket interfaces to support document processing, external integrations, and data management. Requires PostgreSQL and NATS.
-
SnapPipe
Identity-based QUIC transport toolkit with signed tickets, self-hosted relay scaffolding, and zero-vendor open-core lock-in.
-
starmetal
High-performance, self-hosted multi-language package registry and registry proxy
Security Rust -
sycophant
The zero-trust framework for autonomous AI agents.
-
tokenfuse
TokenFuse — runtime control for AI agents: per-run budgets, loop detection, burn forecast, kill-switch. Observability shows the fire; TokenFuse is the automatic extinguisher.
-
tool-gates
Intelligent tool permission gate & security hooks for AI assistants (Claude Code, Codex, Antigravity; Gemini deprecated). Features AST shell gating, file guards, and safety scanners.
-
waveshare-watch-rs
Run Rust no_std firmware on the Waveshare ESP32-S3-Touch-AMOLED with this complete replacement for ESP-IDF and LVGL, featuring custom drivers and Embassy support.
-
WireMCP-rs
Provide high-speed real-time packet capture and network analysis with Rust-powered parsing and threat detection for efficient MCP server use.
Security Rust