agent-security — independent software & tools
-
patient-zero
Supply-chain attack scanner for the agent era. Triage in 30s with `npx patient-zero`, block malicious installs before postinstall runs, or drop into CI as a GitHub Action. Covers npm + Python + MCP agent configs. Free, MIT, no signup, no telemetry.
-
huqan
Local-first, deterministic verification layer for AI claims, memory writes, and risky actions.
-
gecko-surf
The knowledge graph for APIs your agent can trust. Maps any API — even messy, paywalled, or on-chain ones — into a verified graph your agent traverses instead of guessing, and simulates any action to a receipt before money moves.
-
clawseccheck
🦞 Free, local, read-only security self-audit for your own OpenClaw AI-agent setup. Scores it A–F, surfaces the urgent holes, emits copy-paste fixes. Zero deps, no network, no API key — your data never leaves your machine.
-
upstream-radar
Scan and monitor DeepSeek Harness plugins: find exact dependency and compatibility problems, then keep a fixable report for authors and agents.
-
crewscore
Find the safety rules your AI agent prompt forgot. Checks 23 published controls — injection defense, human approval, cost limits, stop conditions. Offline CLI + GitHub Action + in-browser checker. No API key, no LLM.
-
Yana-AI
Personal Agent OS. Deterministic runtime guardrails for AI agents with hooks, policy engine, audit logs, and multi-agent orchestration. Apache 2.0 License
-
abtars
Agent harness connecting messaging platforms, with persistent memory, skills, scheduled tasks, self-healing supervision, and distributed multi-agent collaboration
-
agent-egress-bench
Provide an open test corpus to assess and improve AI agent egress security through validated cases and automated workflows.
-
batesian
Active security scanner for A2A and MCP servers
-
comis
Open-source security-first runtime for AI agents that learn and act across sessions.
-
emilia-protocol
Consequence firewall for machine actions. EMILIA Gate verifies exact authority before money, code, permissions, infrastructure, or regulated state changes; the open protocol makes the evidence independently verifiable.
-
themoltnet
Accountable authority for autonomous agents
-
red-team-blue-team-agent-fabric
AI agent security harness for adversarial testing: 606 executable tests on main, 603 in the v4.15.0 release, across MCP, A2A, x402/L402, decision governance, benchmark integrity, human-in-the-loop, skill supply chain. Commit-pinned OWASP Agentic v1.1 T1-T17 (13 direct, 4 partial), AIUC-1 2026-Q1/Q2 crosswalk 19/20, NIST AI 800-2 aligned.
-
hackmyagent
Metasploit for AI agents: scan, attack, and fix AI agents and MCP servers. Open source security toolkit.
-
aegis-kms
An open-source, KMIP-compliant Key Management Service — usable as an embeddable library or as a standalone server, with first-class support for AI agents.