Open source agent-security projects
Every project in the registry tagged agent-security, ranked by real GitHub adoption.
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in
A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
Agentic LLM Vulnerability Scanner / AI red teaming kit 🧪
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injecti
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API
Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop
Open-source runtime AI agent security tool - monitors and controls AI agents, catching malicious tool use, prompt injection, and policy drift in real time, befo
Related tags
Frequently asked questions
How many open source agent-security projects are there?
This registry tracks 9 projects tagged agent-security, with 34,703 GitHub stars between them. The most-adopted is SkillSpector at 17,624 stars.
Are these agent-security projects free to use?
Yes — 9 of the 9 carry an explicit open-source licence across 2 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.
Which agent-security project should I choose?
The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.
Are these agent-security projects still maintained?
9 of the 9 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.