Security testing that runs inside the coding agent you already use. Source-available, not open source.
Tool-agnostic 13-phase AI development pipeline — turns a task description into reviewed, committed code through automated design, adversarial review, security, test, and code-review gates. One bash engine, balanced Opus/Sonnet routing, self-healing commit review.

MCPify is an AI enablement compiler that transforms existing applications into AI-native, agent-operable systems.
Composable agent runtime with enforced isolation boundaries
Containment for AI agents - user isolation, sandboxed execution, network controls, backup/rollback. TLA+ verified.
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Multi-language agent runtime and library for execution scope management, lifecycle events, and middleware on tool and LLM calls.
OpenGhost is an Agent Skill for authorized web app penetration testing: Enter lab url paste credential your agent and wait everything does with help of openghost
Open-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.
Observability and enforcement for AI agent harnesses. Capture every run and runtime reliability with policy enforcement. 40 built-in policies, a local dashboard, no account required with a generous free cloud plan
Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, in the browser, or in the cloud.