Security Projects

Security projects from Show HN — penetration testing, encryption, privacy tools, and vulnerability scanners.

GitHub

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

1,976Go
●●●Banger

Agent Vault – A HTTP credential proxy and vault for AI agents

Agents never see credentials — brokered access beats retrieval for prompt injection safety.

Zero to OneSolve My Problem
dangtony98
156563mo ago
GitHub

Local-first, encrypted password manager.

221TypeScript
●●●Banger

Bramble – Local-first password manager

P2P password sync via Nostr + WebRTC with zero cloud vault—unlike Bitwarden or 1Password.

WizardryZero to OneSolve My Problem
MegagramEnjoyer
1535027d ago
GitHub

Security firewall for agents

950Go
●●●Banger

Claw Patrol, a security firewall for agents

Wire-protocol parsing gates agent actions before they hit production—no LLM gateway does this.

Big BrainZero to OneSolve My Problem
rough-sea
112311mo ago
GitHub

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

41Python
●●●Banger

Baltic shadow fleet tracker – live AIS, cable proximity alerts

Cable proximity alerts on shadow fleet vessels when MarineTraffic only shows positions.

Dark HorseZero to OneNiche Gem
FormerLabFred
56184mo ago
GitHub

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of duties, and cryptographically signed, offline-verifiable audit logs.

50TypeScript
●●●Banger

Scan your AI agents for dangerous capabilities

Banking-style segregation of duties stops agents from approving their own dangerous tool calls.

Solve My ProblemBig BrainShip It
smashini
441923d ago
GitHub

OS-level runtime auditing for unpredictable automation.

75Go
●●●Banger

Logira – eBPF runtime auditing for AI agent runs

eBPF runtime visibility for AI agents—first tool solving the trust problem with Claude Code and similar.

Solve My ProblemWizardry
melonattacker
2635mo ago
GitHub

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution.

73C
●●●Banger

Z-Jail – A 130 KB Linux sandbox-C99 with 7 defense layers and zero deps

Seven security layers in 130 KB with zero deps fills the bwrap-nsjail gap.

WizardryBig Brain
Zierax
232328d ago
GitHub

Deep research for your infra. Cynative runs frontier models across your code, cloud and runtime - reasoning through GitHub, GitLab, AWS, GCP, Azure and Kubernetes as one system - and comes back with verified answers.

146Go
●●●Banger

Cynative – Read-only CLI in Go that explains your live infrastructure

Sandboxed agent verifies findings across code and runtime where Prowler and Datadog only scan.

Big BrainWizardry
szin
1641d ago
GitHub

auth for agents–from the creator of `dotenv` and `dotenvx`

154JavaScript
●●●Banger

Vestauth – Auth for Agents

Agent auth via key-signing beats API keys and OAuth for autonomous systems.

Big BrainSolve My ProblemZero to One
scottmotte
1115mo ago
GitHub

See what your AI coding agent actually did on your computer. 100% local: every file it opened, every secret that entered its context, every sensitive-read-then-network-call. Zero dependencies, zero network calls.

10TypeScript
●●●Banger

Confessor – replay what private info Claude Code accessed on your PC

Connects sensitive file reads to network calls when compliance loggers miss the link.

Big BrainSolve My Problem
ninjahawk1
11118d ago
GitHub

an implementation of the ideas in Erik Meijer's "Guardians of the Agents: Formal Verification of AI Workflows" (Communications of the ACM, January 2026)

139Python
●●●Banger

Guardians – Verify tool-using agent workflows before execution

Applies formal verification to prevent prompt injection before any tool executes.

WizardryBig BrainZero to One
namin
803mo ago