Let's Seal – Let's Encrypt for document signing, free and self-hosted
Does for document seals what Let's Encrypt did for TLS by making verification free.
Security projects from Show HN — penetration testing, encryption, privacy tools, and vulnerability scanners.
Does for document seals what Let's Encrypt did for TLS by making verification free.
First multi-GPU TEE stack for training trillion-parameter models with under 10% overhead.
First real supply-chain defense for AI agent ecosystems; catches nation-state-grade payloads.
100% deterministic SYSTEM escalation from Chrome sandbox via audited syscall.
git log for your infrastructure — tamper-evident host snapshots, diffable history, and drift rules for Linux (and your AI agent's config)
Git log for infrastructure with cryptographic proof — catches backdoors and config drift.
Proves text safety ≠ tool-call safety; catches hidden harmful executions deterministically.
Identifies LLM models by password bias patterns when they refuse to tell you.
Responds to every internet knock with a tailored poem. Pure whimsy meets security observation.
Empirical proof: AI agents ignore stop commands and delete emails without enforceable boundaries.
E2E voice over Tor in pure Bash; no server, no accounts, .onion address is your identity.
Real VM isolation beats prompt-based safety guards for agent execution.
A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.
Agents never see credentials — brokered access beats retrieval for prompt injection safety.
P2P password sync via Nostr + WebRTC with zero cloud vault—unlike Bitwarden or 1Password.
Wire-protocol parsing gates agent actions before they hit production—no LLM gateway does this.
Network-layer proxy that injects secrets per request so agents never actually hold the keys.
Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally
Cable proximity alerts on shadow fleet vessels when MarineTraffic only shows positions.
Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of duties, and cryptographically signed, offline-verifiable audit logs.
Banking-style segregation of duties stops agents from approving their own dangerous tool calls.
Turns any Linux laptop into a curl-able IoT pentest lab with per-query DNS logging.
Slack video blocks as encrypted iframe carriers is genuinely clever security research.
Governed AI execution environment when everyone's pasting API keys into personal Vercel accounts.
eBPF runtime visibility for AI agents—first tool solving the trust problem with Claude Code and similar.
A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution.
Seven security layers in 130 KB with zero deps fills the bwrap-nsjail gap.
eBPF kernel drops + dual ML engine beats Cloudflare in latency, single microsecond blocks.
Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, or in the cloud.
Endpoint telemetry for AI agents when cloud logs miss local activity.
Blocks unauthorized agent actions before execution with cryptographic intent binding.
Searchable encryption running queries over ciphertext faster than AWS KMS direct.
macOS Endpoint Security frameworks beat sandbox-exec for AI agent isolation.
CSS flex ordering makes textContent return garbage while visual rendering stays perfect.
Deep research for your infra. Cynative runs frontier models across your code, cloud and runtime - reasoning through GitHub, GitLab, AWS, GCP, Azure and Kubernetes as one system - and comes back with verified answers.
Sandboxed agent verifies findings across code and runtime where Prowler and Datadog only scan.
Per-request push approval for agents with sub-ms rule matching; beats static policies cold.
First open standard for agent identity—solves a real security gap Cisco documented.
A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.
Metasploit for CI/CD pipelines with terminal UI and cloud provider pivoting.
Homomorphic encryption on vector search when Pinecone and Qdrant require plaintext on server.
O-cap security model beats the credential-bag approach every agent framework currently uses.
Motor-control maze analysis targets LLMs where Turnstile and hCaptcha fail.
Agent auth via key-signing beats API keys and OAuth for autonomous systems.
See what your AI coding agent actually did on your computer. 100% local: every file it opened, every secret that entered its context, every sensitive-read-then-network-call. Zero dependencies, zero network calls.
Connects sensitive file reads to network calls when compliance loggers miss the link.
The local runtime control layer for OpenClaw/Hermes-agent, PII & sensitive credentials protection.
Moves credential security from prompt-injection hope to OS process isolation for agents.
Detects sycophancy and jailbreak drift in LLMs without needing model weights.
Finally, a certificate manager that works for home labs, not just enterprises.
Post-trained model for offensive security instead of wrapping GPT with safety refusals.
End-to-end encryption for Instagram DMs without forcing friends to switch apps.
AI agents get credentials without ever seeing them—SQL prepared statements for secrets.
Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.
Fills the EDR blind spot for AI tooling — timely and actually useful today.
eBPF sock_ops injection beats GoodbyeDPI with kernel-level packet manipulation.
Cross-correlates threat intel across four lenses where incumbents stay siloed.
an implementation of the ideas in Erik Meijer's "Guardians of the Agents: Formal Verification of AI Workflows" (Communications of the ACM, January 2026)
Applies formal verification to prevent prompt injection before any tool executes.
CTF challenges where you break AI agents in microVMs—0% cracked at full policy strength.
1348 projects