AI coding agents and agent orchestration
AI agent security guardrails
Tools that scan, monitor, gate, audit and red-team AI agents' tool calls and behaviour to block prompt injection, data leaks and risky actions while producing compliance-ready audit trails for teams deploying agents.
Built for: AI agent developers and security/compliance teams
Projects since May 04
180
Different builders
168
Last 4 weeks vs 8 before
+16%
AI is the core
20%
Projects per week
Mostly developer tool or library (41%), web app (21%), api or backend service (15%) · from r/SideProject, r/vibecoding, r/SaaS, r/IMadeThis
Latest
- SCC Runner — Verifies an AI agent's claimed outcomes against real system evidence and returns a verdict.“I built a tool to verify what AI agents actually did”
- Enforly — Checks JSON data against a plain-English policy and returns allow, deny, or review decisions with probabilities.“Built a small "guardrails as an API" thing. Would love honest feedback”
- Kill Switch — Lets operators immediately halt AI agents that behave in unauthorized ways, without relying on the agent's cooperation.“I built a kill switch for AI and AI agents to stop the robot uprising.”
- Kill Switch — Screens LLM inputs and outputs against plain-English rules and blocks or shuts off AI usage on demand.“Kill Switch: A Remote Kill Switch For AI and AI Agents”
- OpenRod — Runs AI coding agents in isolated sandboxes with policy controls for network egress, secrets, and audit logging.“I built an open-source control plane for sandboxing AI coding agents - looking for honest feedback”
- GetMyAIInfo — Checks what AI platforms say about a business and identifies incomplete or inaccurate information and visibility gaps.“My product graveyard has 30 apps. I’m finally launching one”
- Auth Your Agent — Lets an AI agent act on websites without ever seeing the user's password, requiring phone approval for logins and any data-changing actions.“I got tired of choosing between giving my AI agent my passwords and babysitting it at every login page”
- Parad.AI.se — Runs a monthly simulated Garden of Eden where an AI agent gathers fruit while a serpent tempts it with a conflicting prompt, and records each run.“Parad.AI.se – A monthly AI trust experiment in the Garden of Eden”
- CGS — Records AI-related governance events and produces structured analysis of AI decisions, with replayable historical state.“Building CGS: how would you make an AI governance trail replayable?”
- IQRAX — Wraps frontier LLMs in deterministic external controls that qualify agents, gate acceptance of work, and log every input and output with hashes.“I built a device-first deterministic architecture layer for frontier LLMs and published my research. Looking for people to run a narrow test and report back results.”
- AgentPaySec — Runs adversarial attack vectors against LLM shopping agents with checkout tools and shows the resulting unauthorized tool calls.“I stress-tested an autonomous purchasing agent against 16 transactional attacks. 5 bypassed safeguards and authorized rogue charges (Traces & Post-Mortem)”
- AnshinGPT — Scans LLM prompts and model outputs for prompt injection, jailbreaks, sensitive-data leakage and unsafe output via an API.“Looking for 10–20 GenAI developers to test a runtime security API”
- axonpush — Combines app spans, exceptions and AI model or tool calls into one trace, with an optional gateway that redacts PII and caps AI spend.“I built a way to see your app, AI calls and errors in one trace”
- secure-ai-kit-attacks — Replays recorded prompt-injection attacks against an LLM agent's guardrails and reports which guardrails actually change the outcome when removed.“I removed my LLM app's guardrails one at a time and replayed recorded attacks. 4 of the 6 in the chain changed nothing.”
- Sets spending and traffic limits on AI agents and infrastructure, detects abnormal usage, and automatically cuts traffic when limits are exceeded.“I’m building a new saas 1billion dollars , be ready”
- Accord Guard — Detects sensitive identifiers in text locally in the browser and replaces them before they are submitted to generative AI tools.“Built a free, locally running privacy extension for ChatGPT. Looking for feedback from other extension developers.”
- Arcaeon — Records AI agent tool calls in a hash-chained log that can be verified for tampering, and reconciles that log against tool-side records.“If your AI agent keeps a log, who besides you ever checks it?”
- Perslis — Represents application state, rules, and permitted transitions explicitly so AI-generated software can verify conditions before executing actions.“Vibe coding made software incredibly fast to create. Perslis is about making that software understand and enforce what must be true.”
- cogext-primitive — Extracts commitments and deadlines from text and tracks them in local SQLite through open, due, overdue and fulfilled states.“Shipped a local commitment extractor for AI agents — 48 tests, MIT licensed, pip install”
- Patronus — Scans pasted text, public URLs and uploaded documents for hidden prompt injection instructions aimed at AI assistants.“We made a web tool for checking text and documents for prompt injection”
Most discussed
- Is this slop? test — Provides a simple open-source test for judging whether a piece of content is low-quality AI slop.“I just open sourced my "Is this slop?" simple test”
- jeview — Visualizes the decisions made by Jev through a local gateway to its API.“I built a free Jev visualizer after burning 5bn tokens in three days”
- Checks AI assistant responses before they reach users and flags possible violations of privacy, financial, and sanctions regulations.“One year building, three months selling, zero customers. Frustrated and exhausted - where did I go wrong? i will not promote”
- overyourshoulder — Monitors outbound browser requests to AI services and produces a daily report with a leak score, destination countries, and busiest hour.“Made a Chrome extension that scores how much you leak to AI per day. My own score is embarrassing.”
- infrarails — Scans Terraform for AWS Bedrock infrastructure and reports whether EU AI Act, NIST AI RMF, and ISO 42001 controls pass, fail, or can't be verified.“I built an open-source compliance scanner for AI infrastructure on AWS - looking for feedback”
- Monitors AI agents in production to show what they do and where they fail.“I boosted the same post in Tokyo and San Francisco for 24 hours. 10,085 impressions, 7 clicks, 0 signups. Numbers inside.”
- replayd — Captures failed AI agent runs as tests and replays them to catch regressions before deploy.“replayd — regression testing for AI agents, just shipped v0.1.0”
- Orlera — Maps a business's AI systems, assesses their risks, identifies missing controls, and generates audit-ready reports.“Tips on getting users in the pre launch to launch stage?”
- World2Agent — Lets AI agents monitor web sources through installable sensor packages and push alerts when something relevant appears.“I got tired of passive AI waiting for prompts, so I built a side project to give Agents "ears" (just hit 1.2k stars)”
- TrustLoopGuard — Acts as a separate permission checkpoint that controls which users can call which AI agent tools, what actions are allowed, and when a human must approve.“Most AI agent SaaS is just bad security with a nice dashboard”