llm-security — independent software & tools
-
huqan
Local-first, deterministic verification layer for AI claims, memory writes, and risky actions.
-
attestral
Open-source security scanner for MCP servers and AI agents: finds prompt injection, tool poisoning, and excessive agency, and models the cloud your agents can reach. pip install attestral.
-
AI-Security-Platform
Control plane for enterprise AI security: inline runtime guardrails, automated red teaming with auto-remediation, AI asset posture (AI-SPM), and compliance governance. Python control plane + Go inline agent.
-
conarium
Conarium AI — self-hosted governance layer between AI assistants and your real data. Deterministic PII masking, allow/deny policy, hash-chained audit, an Ed25519-signed receipt per access verifiable offline, coverage reconciliation against the DB's own query counters to surface gateway bypasses, and conformance vectors. MCP-native. MIT.
-
clawseccheck
🦞 Free, local, read-only security self-audit for your own OpenClaw AI-agent setup. Scores it A–F, surfaces the urgent holes, emits copy-paste fixes. Zero deps, no network, no API key — your data never leaves your machine.
-
ai-privacy-gateway
你的 AI 数据正在裸奔,30 秒装上防火墙。开源的 AI API 隐私隔离网关。
-
crewscore
Find the safety rules your AI agent prompt forgot. Checks 23 published controls — injection defense, human approval, cost limits, stop conditions. Offline CLI + GitHub Action + in-browser checker. No API key, no LLM.
-
mcp-safeguard
🛡️ Automated security scanner for MCP (Model Context Protocol) servers — 52 rules for prompt injection, credential exposure, SSRF & tool poisoning. pip install mcp-safeguard
-
pentest-mcp-server
Integrate penetration testing tools and payloads into your workflow through the Model Context Protocol using STDIO or HTTP.
-
tool-gates
Intelligent tool permission gate & security hooks for AI assistants (Claude Code, Codex, Antigravity; Gemini deprecated). Features AST shell gating, file guards, and safety scanners.
-
MCPScan
Scan and identify security issues in MCP servers to help strengthen defenses against potential attacks on AI agent connections.
-
agent-bom
AI supply-chain & cloud security scanner and self-hosted control plane — agents, MCP, packages, cloud estate, non-human identities, and LLM cost. SBOM/SARIF, graph attack-paths, runtime enforcement, and compliance evidence.
-
agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
-
nuguard
AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.
-
hackmyagent
Metasploit for AI agents: scan, attack, and fix AI agents and MCP servers. Open source security toolkit.
-
synentra
Intent‑aware governance gateway for autonomous AI agents that interact with enterprise APIs.
-
ZugaShield
7-layer AI agent security system — stop prompt injection, data exfiltration, and AI-specific attacks in under 15ms. Zero dependencies.