SigmaShake - AI Agent Guardrails at Runtime
SigmaShake adds deterministic sub-2ms guardrails to Claude Code, Cursor, Gemini CLI, and Copilot - blocking destructive tool calls before they execute.
Tag
44 posts tagged #security
Browse 44 posts tagged Security, including practical setup notes, reviews, comparisons, and workflow patterns for engineers working with AI tools.
SigmaShake adds deterministic sub-2ms guardrails to Claude Code, Cursor, Gemini CLI, and Copilot - blocking destructive tool calls before they execute.
PenPeeper is a free, open-source pentesting engagement manager that combines AI-powered vulnerability analysis with Nmap, Nikto, and FFUF scanning, CVE lookup, and professional report generation.
DepsGuard is a zero-dependency Rust CLI that scans your npm, pnpm, yarn, bun, uv, pip, and poetry configs for supply chain security gaps and applies fixes interactively.
Run any AI agent in a zero-latency kernel-enforced sandbox with zero setup. Nono isolates agents and their tools with least-privilege policies, credential proxying, and L7 API filtering.
Open-source gateway that stores API credentials once and injects them transparently for AI agents. Never give agents your real keys.
ScopeGate is an open-source MCP proxy that gives each AI agent exactly the access it needs — nothing more. Connect Google services, define granular OAuth scopes, and get an MCP endpoint URL in minutes.
Cordon is an open-source security gateway that sits between AI agents and MCP servers, enforcing policy-based access control with human-in-the-loop approvals.
Open-source platform for securing AI agents with fine-grained policies, runtime enforcement, and tamper-evident audit logs. Apache-2.0.
Kastra intercepts AI coding agent tool calls and evaluates them against deterministic policies before execution. Built after a near-miss with a production DELETE query.
Production-ready MCP server bridging Ghidra's reverse engineering capabilities with AI tools and automation frameworks. 256 tools, Docker headless mode, convention enforcement.
VibeShield transforms developer intent into secure, production-ready code via a real-time security mediation layer that converts natural language requests into precise engineering specs with built-in security requirements.
Exfault is an autonomous mobile security researcher for Android apps, using AI agents, static analysis, dynamic analysis, authenticated workflows, and real Android cloud emulators to produce reproducible security findings.
owthorize is a synchronous Node.js guard that parses SQL, HTTP, shell, and filesystem tool calls into typed shapes and evaluates them against rules — catching destructive AI agent actions before they execute.
certgrep is a free tool that searches Certificate Transparency logs to find domain squatting and phishing attempts against your brand, built by the Have I Been Squatted team.
Intercept, audit, and validate AI agent tool calls before execution. Viberails adds a security layer between AI agents and their operations with under 50ms latency.
CloudGrip connects GitHub, GitLab, and Slack with a code review agent and Cerberus vulnerability scans to govern AI-generated code before it reaches production.
Octelium is a self-hosted, open-source unified zero trust platform combining VPN, ZTNA, secure tunnels, AI gateway, and MCP gateway in one install.
AgentLair gives AI agents a persistent email identity, encrypted credential storage, and namespace isolation via a single API — no OAuth, no human in the loop.
Post-trained AI pen testing tool that actually runs exploits against your own infrastructure, backed by 2M free tokens on signup.
Before installing an MCP server, check its trust score, permission map, and security report. Vet maintains a free registry of 136K+ AI tools and MCP servers.
Self-hosted security SIEM that runs on 2 vCPU and 4 GB RAM. Sub-second search across billions of events, AI-assisted triage, and a managed cluster on every plan.
Rigour is an open-source governance layer for AI coding agents that scans for secrets, enforces code quality, and controls agent memory in real time.
Infisical is an open-source platform for syncing secrets, certs, and environment variables across your team and infrastructure. Self-host or use cloud.
APIRadar monitors millions of public GitHub repositories in real time, surfacing exposed API keys for OpenAI, Claude, Gemini and other providers before they get weaponized.
EnvMark uses Git as a backend to manage and share .env files across teams. No server, no third-party storage—just Git branches for environment isolation.
A production-ready MCP server bridging Ghidra's binary analysis engine with AI agents. Covers 251 tools, P-code emulation, live debugger integration, and Docker headless mode.
Production-grade middleware that intercepts AI agent tool calls, evaluates them against policy, and blocks or logs risky actions before execution.
Reality Defender API detects AI-generated deepfakes in images, audio, and video. Enterprise-grade verification for platforms and institutions.
Open-source multi-cloud security and compliance verification tool. Monitors AWS, Azure, GCP, and OCI with instant alerting and low infrastructure overhead.
Live tracking of exposed API keys from millions of GitHub repositories. Analyze exposure trends to mitigate organizational security risks with unmatched detail and speed.
Capframe maps every tool your AI agents reach, mints scoped capability tokens in Rust, and enforces runtime policy decisions in microseconds—no LLM in the path.
Policy-as-code authorization built for AI agents, with OPA-native design, AuthZEN alignment, and agent-operable access workflows through MCP integration.
agentcookie syncs Chrome cookies, CLI bearer tokens, and API keys between Macs over Tailscale so agent machines stay authenticated without repeated logins.
AccessOwl is a YC-backed SaaS management platform that provides access governance, Shadow IT detection, and automated user provisioning for Google Workspace and Microsoft 365 environments.
SuperHQ runs Claude Code, Codex, and custom AI agents in isolated microVMs on macOS. Each agent gets its own sandbox with secure auth gateway and diff review.
Open-source SQL workbench with end-to-end encrypted credentials, access requests, and audit logs. Free hosted or self-hosted deployment for secure database access.
Run AI agents in hardware-encrypted TEEs backed by AMD SEV-SNP. Private inference, vTPM-bound keys, and TEE-attested execution for OpenClaw workloads.
Infisical is an open-source identity security platform for developers, machines, and AI agents. Manage secrets, certificates, and access with self-hosted or cloud deployment.
Browse, discover, and safely run AI tools with cryptographic verification. Enact is the npm for AI agents—a registry with end-to-end proofs that tools do.
Jibril uses eBPF to monitor and enforce runtime security policies directly in the Linux kernel — deploy a single binary with negligible overhead and real-time.
Reality Defender launches a public API for real-time multimodal deepfake detection across images, voice, video, and text — with SDKs in Python, Java, Rust.
Didit consolidates KYC, AML, biometrics, authentication, and fraud prevention into a single API integration — no more stitching together five providers for.
Jibril uses eBPF to monitor and enforce security policies directly in the Linux kernel, protecting ephemeral cloud workloads in real time with negligible.
Tinfoil runs open-source LLMs on cloud GPUs with hardware-backed privacy guarantees. Your data never leaves the secure enclave—not even Tinfoil can access it.