A curated list of resources for AI agent identity, authorization, coordination, and security.
As AI agents move from demos to production, securing them becomes critical. This list covers tools, frameworks, papers, standards, and best practices for making AI agents trustworthy.
Contributions welcome! See CONTRIBUTING.md for guidelines.
- Identity and Authentication
- Authorization and Policy
- Agent Coordination
- Sandboxed Execution
- Security Monitoring
- Standards and Protocols
- Papers and Research
- Incidents and Case Studies
- Talks and Presentations
- Books and Guides
Tools and platforms for giving AI agents verifiable identities.
- Authora Identity - Cryptographic agent identities (Ed25519), RBAC, delegation chains (RFC 8693), MCP authorization, policy engines, approval workflows, audit logging. SDKs in TypeScript, Python, Rust, Go.
- Permit.io - Fine-grained authorization with agentic identity support. Intent-based identity, MCP gateway, built on OPA/OPAL.
- Oso - Authorization framework with Polar policy language. Agent Security product with scope/watch/enforce/audit.
- SPIFFE/SPIRE - Secure Production Identity Framework for Everyone. Workload identity standard applicable to agent systems.
- Sigstore - Keyless signing for software artifacts. Applicable to agent action signing.
Frameworks for controlling what AI agents can do.
- OPA (Open Policy Agent) - General-purpose policy engine using Rego language. Widely used for infrastructure policy, adaptable for agent authorization.
- Cedar - Policy language by AWS for fine-grained authorization. Used in Amazon Verified Permissions.
- Casbin - Authorization library supporting ACL, RBAC, ABAC models. Implementations in Go, Java, Node.js, Python.
- OpenFGA - Fine-grained authorization inspired by Google Zanzibar. Good for relationship-based agent permissions.
- Cerbos - Access control with YAML policies. API-first, self-hosted.
Tools for coordinating multiple AI agents working together.
- AgentSync - File-level locking, sprint management, messaging, and coordination for AI coding agents on shared codebases.
- LangGraph - Framework for building stateful, multi-agent applications with LangChain.
- CrewAI - Framework for orchestrating autonomous AI agents with role-based task execution.
- AutoGen - Microsoft's framework for building multi-agent conversational systems.
- OpenHands - Platform for AI software development agents.
Secure environments for running AI agent code.
- AgentNet - Task execution marketplace with sandboxed workers, encrypted vault, Security Intelligence Platform (SIP).
- E2B - Open-source sandboxed execution using Firecracker microVMs. Code interpretation and data analysis.
- Modal - Cloud infrastructure for AI with sandboxed containers, GPU scaling, and batch processing.
- Daytona - Secure infrastructure for running AI-generated code with isolated environments.
- Fly.io Machines - Lightweight VMs for running untrusted workloads at the edge.
Detecting and responding to AI agent threats.
- Authora SIP - Security Intelligence Platform with 36 detection rules, 8 SIEM export connectors (Splunk, Datadog, PagerDuty), SOAR callback API, OCSF/CEF compliance.
- Caldera - Automated adversary emulation by MITRE. Adaptable for testing agent security.
- Falco - Cloud-native runtime security. Detects anomalous behavior in containers running agents.
- Wiz - Cloud security platform with AI workload protection.
Standards relevant to AI agent security.
- MCP (Model Context Protocol) - Protocol for AI model-tool interaction. Defines how agents access external tools and data.
- RFC 8693 - OAuth 2.0 Token Exchange - Standard for delegated access. Foundation for user-to-agent and agent-to-agent delegation.
- OCSF (Open Cybersecurity Schema Framework) - Standardized security event format. Used by SIP for SIEM integration.
- NIST AI Risk Management Framework - Guidelines for managing AI risks including agent autonomy.
- OWASP Top 10 for LLM Applications - Security risks for LLM-based systems including prompt injection and insecure tool use.
- Ed25519 - High-speed, high-security digital signature scheme used for agent identity.
Academic and industry research on AI agent security.
- Toolformer: Language Models Can Teach Themselves to Use Tools - Foundational paper on LLM tool use.
- ReAct: Synergizing Reasoning and Acting in Language Models - Reasoning + acting paradigm for agents.
- The Landscape of Emerging AI Agent Architectures - Survey of multi-agent system architectures.
- Prompt Injection Attacks Against LLM-Integrated Applications - Security analysis of prompt injection in agent systems.
- Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications - Real-world attack vectors on LLM tool-calling systems.
Real-world security incidents involving AI agents.
- LiteLLM Supply Chain Attack (2025) - Compromised dependency in widely-used LLM proxy.
- 29 Million Secrets Leaked on GitHub (2024) - AI coding tools accelerating secret exposure.
- ChatGPT Plugin Permission Escalation - Demonstration of cross-plugin attacks via shared context.
- Simon Willison - Prompt Injection and AI Security - Ongoing coverage of LLM security issues.
- OWASP AppSec - LLM Security - Community presentations on LLM application security.
- LLM Security Guide - Comprehensive guide to securing LLM applications.
- Anthropic's Responsible Scaling Policy - Framework for safely deploying capable AI systems.
Contributions are welcome! Please read the contribution guidelines first.
This list is released under CC0. You can copy, modify, and distribute it without asking permission.