Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

OpenWorkProof: Verify and Accept AI Agent Work
OpenWorkProof is an open protocol for authorizing AI agent tasks and recording verifiable execution evidence. It helps teams independently review whether work stayed within scope, then keep verification separate from human acceptance.

DeclarAgent: Run Auditable Workflows for AI Agents
DeclarAgent executes YAML runbooks through a CLI or MCP server, giving AI agents a structured way to validate, preview, and run multi-step workflows. It suits teams that want reusable plans and explicit controls around side effects.

intent-plane: Gate Agent Actions With Auditable Authorization
intent-plane is a Go authorization gate for agent actions that can have irreversible effects. It checks declared intents against signed policy and records decisions for independent verification, with a fail-closed posture when evaluation is uncertain.

SkillSpector: Scan AI Agent Skills for Security Risks
SkillSpector scans AI agent skills before installation, flagging suspicious instructions, risky code, and supply-chain issues. Use it for pre-install reviews, CI gates, or MCP-based scanning, with optional LLM analysis for context.

OpenBot: Govern and Run AI Coworkers on Your Infrastructure
OpenBot is a self-hosted platform for running AI coworkers with their own browser, files and tools. It connects agents through AG-UI and routes computer actions through configurable policy and audit controls.

mdx-a2ui: Convert MDX to A2UI JSON
mdx-a2ui converts prose and approved components in MDX into A2UI JSON without evaluating the source. It is an experimental option for agents or tools that author MDX but need structured output for A2UI renderers.

aidevops: Coordinate AI Agents Across Development and Operations
An OpenCode plugin and shell-based framework for coordinating AI agents across software delivery, DevOps, and business workflows. It combines specialist guidance with isolated Git work, verification, and automation for teams seeking a more durable alternative to one-off AI chats.

guardvibe: Scan AI-Written Code for Security Issues
GuardVibe is a local security scanner and MCP server for developers building with AI coding agents. It checks code, dependencies, configuration, and prompts, with rules tailored to modern web stacks.

tunnel-client: Connect Private MCP Servers to OpenAI
A Go client that connects private or localhost MCP servers to ChatGPT, Codex, the Responses API, and AgentKit through an OpenAI-hosted tunnel. It is designed for teams that need remote access without exposing MCP servers to the public internet.

gh-aw: Build AI-Powered Repository Workflows
gh-aw is a GitHub CLI extension for defining AI-powered repository automation in Markdown and running it through GitHub Actions. It suits teams adding agent reasoning to tasks that are difficult to express as deterministic scripts.

agent-sandbox: Run Isolated Sandboxes for AI Agents
Agent-Sandbox provides a self-hosted Kubernetes service for creating and managing isolated environments for AI agent code and actions. It wraps sandbox lifecycle operations in a REST API and MCP server, with E2B compatibility.

ECC: Equip Coding Agents with Reusable Engineering Workflows
ECC is a toolkit for adding structured engineering workflows to AI coding agents. It combines reusable skills, specialized agents, hooks, memory, and security scanning, with support across Claude Code and several other harnesses.