AgentDish directory
security
Accepted listings with this tag.
| Listing | Category | Score | Trend | Checked | |
|---|---|---|---|---|---|
|
#5
↑ +4
Snyk Agent Scan
Open-source security scanner for AI agents, MCP servers, and agent skills. It auto-discovers installed agent components and checks them for prompt injection, tool poisoning, secrets, malware payloads, and related risks. |
Security / Agent Security | 92 | ↑ +4 | 45 days ago | Details |
|
#40
→ 0
Bright Security Agent
GitHub Marketplace app from NeuraLegion that scans apps and APIs for vulnerabilities, proposes fixes, and validates remediations inside GitHub workflows. |
Security / Application Security | 89 | → 0 | 13 days ago | Details |
|
#42
→ 0
Redact
Browser extension that scans pastes for credentials and PII before they reach LLM chat sites, with local on-device inference and no network calls. |
Developer Tool / Browser Extension | 89 | → 0 | 17 days ago | Details |
|
#98
↓ -3
Recursant
Open-source platform for governing AI agents across clouds and stacks, with a control plane, sidecar-based data plane, policy enforcement, observability, and audit trails. |
Developer Tools / AI Infrastructure | 88 | ↓ -3 | 44 days ago | Details |
|
#146
↓ -3
Recursant
Open-source agentic mesh for governing AI agents across enterprise systems, with identity, policy enforcement, audit trails, observability, and Kubernetes-native deployment. |
Developer Tools / Code Assistant | 87 | ↓ -3 | 45 days ago | Details |
|
#159
↑ +2
Nenya
An AI API gateway/proxy in Go that sits between coding clients and upstream LLM providers, with request routing, secret redaction, context handling, MCP tool integration, and transparent SSE streaming. |
Developer Tools / AI API Gateway / Proxy | 86 | ↑ +2 | 7 days ago | Details |
|
#176
↑ +2
diplomat-agent-ts
A TypeScript static scanner that finds AI agent tool calls with no checks before they can trigger real-world side effects. It supports CLI scanning, JSON output, a generated tool-call registry, and CI/pre-commit enforcement. |
Developer Tools / AI Code Analysis | 86 | ↑ +2 | 23 days ago | Details |
|
#181
↑ +2
Aperion Shield v0.7
Local guardrails for AI coding agents that intercept destructive actions before they execute, now extended to Git hooks for commit and push enforcement. |
Developer Tools / AI Coding Guardrails | 86 | ↑ +2 | 25 days ago | Details |
|
#193
↑ +2
badvibes
A zero-config CLI that scans repositories for AI-slop patterns like missing .env.example files, committed secrets, large files, duplicated code, TODO drift, and missing tests, then returns a Vibe Score from 0 to 100. |
Developer Tools / Code Quality | 86 | ↑ +2 | 32 days ago | Details |
|
#194
↑ +2
Beacon
Beacon is an open-source endpoint telemetry layer for local AI agents. It captures supported activity from tools like Claude Code, Codex CLI, Gemini CLI, OpenCode, Factory Droid, Claude Cowork, and Cursor, then normalizes events for local inspection or forwarding to SIEM pipelines. |
Developer Tools / Observability | 86 | ↑ +2 | 32 days ago | Details |
|
#249
↓ -3
HoneyLabs
A honeypot telemetry and threat intelligence service with searchable IP lookups, recent scanner data, and an MCP/JSON-RPC API for agents and developers. |
Security / Threat Intelligence | 85 | ↓ -3 | 33 days ago | Details |
|
#279
↓ -6
agent-vault-proxy
A loopback HTTPS proxy that swaps placeholders for real API keys at request time, keeping secrets out of the agent process. It uses Bitwarden Secrets Manager and supports scoped bindings for hosts, methods, and paths. |
Developer Tool / Security | 84 | ↓ -6 | 8 days ago | Details |
|
#287
↓ -6
AgentTrust ID
Runtime authorization platform for AI agents with open-source SDKs in Python, TypeScript, Go, Java, and Rust. The page says the hosted service is in production, supports per-action checks, scoped delegation, revocable tokens, and a shared authorization model across MCP tools, agent-to-agent calls, and direct API integr |
AI Developer Tool / Agent Security / Authorization | 84 | ↓ -6 | 12 days ago | Details |
|
#289
↓ -6
Sandfence
A minimal native macOS sandbox for running Claude Code or Codex with OS-enforced limits on what the agent can touch. |
Developer Tools / Security | 84 | ↓ -6 | 14 days ago | Details |
|
#293
↓ -6
Defending Code Reference Harness
An open-source reference implementation for autonomous vulnerability discovery and remediation with Claude. It includes Claude Code skills for threat modeling, scanning, triage, patching, plus a harness for running a recon → find → verify → report → patch pipeline. |
Security / AI Security | 84 | ↓ -6 | 15 days ago | Details |
|
#305
↓ -6
mcpguard
Open-source security scanner and firewall for MCP servers. It scans configs for common MCP risks, enforces runtime policies on tool calls, and produces audit logs, with CLI commands, policy examples, and a programmatic API. |
Developer Tools / Security | 84 | ↓ -6 | 20 days ago | Details |
|
#317
↓ -6
terminal-guardian-mcp
A secure Model Context Protocol server that gives AI assistants controlled terminal access with risk analysis, sandboxing, logging, filesystem protection, and optional Docker and Git features. |
Developer Tools / MCP Servers | 84 | ↓ -6 | 28 days ago | Details |
|
#336
↓ -6
AI Action Path Lab
An interactive lab for tracing how AI-assisted engineering workflows can reach repos, CI/CD, credentials, tools, approvals, and proof trails. |
Productivity / Workflow Automation | 84 | ↓ -6 | 37 days ago | Details |
|
#360
↑ +63
Faramesh
Runtime governance and containment for AI agents. Faramesh sits between an agent and its tools to enforce policy checks, approval steps, credential isolation, and tamper-evident audit logs before risky actions execute. |
Developer Tools / AI Governance / Agent Security | 84 | ↑ +63 | 45 days ago | Details |
|
#375
↑ +118
Trent AI Claude Code Security
A security product for Claude Code that reviews application architecture inside the IDE via MCP, with contextual assessments, prioritized mitigations, and continuous re-checks as the codebase changes. |
AI Security / AI Application Security | 84 | ↑ +118 | 46 days ago | Details |
|
#392
↓ -3
VaultS3
VaultS3 is a self-hosted, S3-compatible object storage server with a built-in dashboard, low RAM usage, and a single-binary deployment. The page highlights features like versioning, WORM, S3 Select, FUSE mount, IAM/OIDC login, search, and event notifications. |
Developer Tools / Storage | 83 | ↓ -3 | 12 days ago | Details |
|
#417
↓ -3
Deckard
A Mac-resident MCP server that lets AI agents access Apple services like Mail, Calendar, iCloud Drive, Voice Memos, Reminders, and Contacts over a Tailscale network with per-token ACLs and audit logging. |
Developer Tool / MCP Server | 83 | ↓ -3 | 37 days ago | Details |
|
#418
↓ -3
HookGuard
HookGuard is a CLI security scanner for AI coding agent configuration files. It looks for malicious hooks, invisible Unicode, credential exfiltration patterns, and prompt-injection text in files like CLAUDE.md, AGENTS.md, Cursor rules, and GitHub Copilot instructions. |
Developer Tools / Security | 83 | ↓ -3 | 37 days ago | Details |
|
#436
↓ -2
git-lrc
git-lrc is a Git-based AI code review tool that runs on commit and surfaces risk categories, inline findings, and a summary deck for each review. |
Developer Tools / Code Review | 82 | ↓ -2 | 4 days ago | Details |