Topic: agent-security-tools

17 repositories

We5ter/Scanners-Box

The Ultimate Open-Source Security Arsenal for Hackers, Enterprises, and AI Agents——面向极客、企业与 AI 智能体的全域开源网络安全工具矩阵

★ 9,077Forks 2,420

votal-ai-hq/ai-red-teaming

Whitebox & Blackbox AI red-teaming framework for LLMs & Agentic AI apps. It analyzes your app's source code to discover tools, roles, and guardrails, then generates new attacks chains across several categories and adapts over multiple multi turn rounds to find vulnerabilities

★ 35TypeScriptForks 14

putervision/WebCrypt

Zero-dependency Web Crypto suite & Model Context Protocol (MCP) server for AES-256-GCM, RSA-4096, and AI agent security.

★ 28JavaScriptForks 5

stashbase/cli

Open-source access layer for coding agents. Scoped secrets, APIs, tools, files, and dependencies for Claude Code, Codex, Cursor, and more.

★ 9RustForks 0

YashvantHange/AgentArmor

🛡️ Open-source AI security scanner & LLM red-teaming platform. Test LLM APIs, chatbots, agents, MCP servers & RAG for prompt injection, jailbreaks, data leaks & unsafe tool use — with OWASP LLM Top 10 mapping and plain-English, audit-ready reports.

★ 4PythonForks 0

xinbetween/learn-agent-security-from-scratch

A free course on AI agent security: prompt injection, tool poisoning, memory attacks, MCP supply chain, CaMeL, information-flow control, sandboxing and red-teaming. 27 chapters, runnable Python, interactive labs, six projects.

★ 3JavaScriptForks 0

freshxiaoyao/openclaw-human-gate

Manual Verification Protection + AI Selector Compatible with OpenClaw . This is a complete TypeScript plugin project—a true implementation of the `before_tool_call` hook that can intercept tool calls, follow OpenClaw’s built-in approval workflow, and features an approval window mechanism.

★ 2TypeScriptForks 0

thepeternemec/TailorLayer

Evidence-first security review for agent repositories: source-linked findings, suggested fixes, drift checks, and least-privilege launch plans.

★ 1JavaScriptForks 0

mlawsonking/MCP

Deterministic guards and web tools for AI agents (MCP + HTTP APIs)

★ 1JavaScriptForks 0

putmanmodel/kingpin-weak-signal-demo

Runtime capability governance for AI agents. Kingpin separates what an agent notices or believes from what it is authorized to do, using scoped leases, human review, retry controls, prompt-injection handling, and deterministic audit behavior.

★ 0TypeScriptForks 0

rootkiller6788/dsh-plugin-scanner

A plugin-native security scanner for DeepSeek Harness that detects capability escalation, config hijacking, prompt injection, dangerous code, and self-modifying behavior.

★ 0TypeScriptForks 0

srimontidutta/AgentRiskBOM

AgentRiskBOM provides a security bill of materials for reviewing the delegated authority of tool-using AI agents.

★ 0Forks 0

siju-asari/agent-maestro-scnnaer

Discovers agents — A2A protocol agents via their published Agent Card, or plain OpenAPI/Swagger REST services that don't speak A2A at all — then runs a rule-based threat analysis against each one using the MAESTRO framework (Multi-Agent Environment, Security, Threat, Risk, and Outcome — CSA's 7-layer threat model for agentic AI).

★ 0PythonForks 0

alemarcosa/daedalab

Daedalab is a control layer for AI agents that intercepts tool calls, blocks dangerous actions, enforces spending limits, and keeps a complete audit trail, giving users control over what their agents can do before it happens.

★ 0TypeScriptForks 0

psandhir/horustrace

Open-source static security analysis for agentic systems, with dependency graphs, capability tracing, MCP analysis and attack-path detection.

★ 0PythonForks 0