AI Dev Impact Lab JA
← Topics ranking · 2026-08
GITHUB TOPIC

#guardrails

GitHub repositories that have self-applied the topic "guardrails" — a creator-tagged metadata that surfaces how AI projects describe themselves.

30
tagged repos
271
top 30 stars
10
with tool sigs
30
shown

REPOS Repos for #guardrails (top 30 by stars)

paladini/harness-score

Your AI coding agent is only as reliable as the harness around it. Measure that harness in seconds with harness-score.

TypeScript 172 AI 70 Solo 2 sig live ↗
SihyeonJeon/why-was-fable-banned

Fable-style spec + evidence gate for Claude Code + Codex. Makes Opus/Codex work under Fable-like discipline: blocks every edit until a deterministic spec passes, and there is no "done" without live acceptance evidence. Spec-first, verification-gated, forbidden-paths enforced.

Python 47 AI 70
anthony-chaudhary/fak

fak — the Fused Agent Kernel: one Go binary that turns a tool-using agent (Claude Code, Codex, Cursor, any OpenAI/Anthropic/MCP client) into a managed agent: cache-stable model traffic, context compaction + crash resume, nanosecond tool-call policy, local GGUF serving with SSD expert offload.

Go 30 AI 50 Solo 7 sig live ↗
sgaabdu4/hard-eng

Stateful agentic engineering workflow for local coding agents

Python 5 AI 45 2 sig
prat3ik/evalbot

EvalBot — local-first chatbot security & quality evaluation (FastAPI + Next.js). Evaluate chatbot answers against your own docs & guidelines with ML/NLP + AI-judge scoring. Apache-2.0.

Python 3 AI 70
doivamong/agent-workbench

A practical workbench of tools + methodology for solo devs driving an AI coding agent (Claude Code, Cursor, Copilot): safety hooks, secrets crypto, invariant + test-selection tooling, leak scanner, plus skill & memory system templates.

Python 2 AI 100 2 sig
germankovacevic-lab/agent-audit-gate

An audit gate for AI agent outbound messaging: hold the draft, let a senior agent review it (no private-data leak, prompt-injection resistance), then release. Reference implementation.

TypeScript 2 AI 100
Mehtabk/DeeplyAgentic

Building smart, scalable AI agent systems. Harness AI. Reclaim Time. Amplify Impact.

Python 2 AI 70
Vadale/project-guardian

AI Guardian Firewall — a local, user-space, agent-agnostic firewall that mediates an autonomous AI agent's actions (files, shell, network, services) with a deterministic policy boundary, a tamper-evident audit log, and a human-in-the-loop approval cockpit. No kernel modules. Apache-2.0.

Rust 2 AI 70
bharath31/nominee

The authorization layer for AI agents — allow/deny/ask policy, human approvals, and tamper-evident receipts on every tool call. Zero-dep, framework-neutral, no SaaS.

TypeScript 2 AI 70 Solo 2 sig live ↗
Bobcatsfan33/Pharos

The trust control plane for enterprise AI agents — real-time policy verdicts in under 800ms and litigation-grade evidence of every decision. Pharos decides. Pharos proves.

TypeScript 2 AI 70
coreyhiggins/blastradius

How far does this command reach? Guards AI coding agents against shell commands that leave your machine. Zero dependencies.

JavaScript 1 AI 70 Solo live ↗
rmednitzer/agents

Execution substrate for governed agentic workloads; behavioral contracts, action budgets, pluggable memory, and portable skill bundles

Python 1 AI 45 1 sig
jihedbfr-art/ai-skills

Pragmatic AI Engineering Skills Library for LLMs, RAG, Agents, MCP & Spring AI

0 AI 100
kalyvask/ai-safety-os

Same agent action, safe or dangerous by context: email team vs investor; delete scratch vs prod config. A safety layer routes each action: auto, confirm, escalate, block. A reading model auto-executes 0% of unsafe actions vs a baseline's 38% (McNemar p<0.001). Plus a runtime loop: an agent earns or loses autonomy with each counterparty over time.

Python 0 AI 100
alexcao11/ai-llm-automation-systems

AI/LLM automation reference: RAG, tool calling, human review, evals, observability, safety gates, and local deterministic samples.

Python 0 AI 100
AnonZ7/agentic-rag-eval-harness

Production-shaped agentic RAG: LangGraph plan->act->verify agent + hybrid retrieval + guardrails + an eval gate in CI. Provider-agnostic; runs offline with no keys.

Python 0 AI 100
Hal-Hanami/incident-triage-agent

Read-only first-pass incident triage on the Claude Agent SDK + MCP: classifies an alert, retrieves the matching runbook, and proposes a cited first response — or abstains to a human. Measured over four runs: 100% abstention with 0 missed escalations, ~$0.014 per incident.

Python 0 AI 100
galassoray/ai-fpa-variance-copilot

Finance-owned FP&A tool where code computes every number and the LLM only explains — with a deterministic audit proving zero fabricated figures. Synthetic SaaS data.

Python 0 AI 100
Yacineutt/AI-AgenticSafe

AI AgenticSafe - stop your AI agent from breaking production at 3 a.m. 8 battle-tested doctrines, 3 real post-mortems, zero dependencies. By Yacine Mahboub, Founder of WEVIA.

0 AI 100 Solo live ↗
sukikeeling/switchback

Switchback Governance · 折返治理 — the human-in-the-loop governance layer for multi-agent teams (GOAI 2026 Track 1)

Python 0 AI 70
YosefHayim/dufflebag

TypeScript CLI for installing agent skills, hooks, and CI/publish templates for Claude Code and related tools.

TypeScript 0 AI 70 Solo 3 sig live ↗
Jott2121/sabot

Do your agent pipeline's own checks catch planted faults? Measured on LangGraph, CrewAI and AutoGen: median 16.7%. One prompt-level change takes it to 55.0%. Pre-registered spec, Apache-2.0 harness, every raw trace published.

Python 0 AI 70 Solo live ↗
tanrendev/jig

My Claude Code toolkit. Currently guard: hooks that scan agent-driven package installs before they run.

Python 0 AI 70 1 sig
suzuke/agentic-git

A guarded, transparent git for AI coding agents — PATH shim with per-agent worktree routing, deny guardrails, commit provenance, and audited bypass

Rust 0 AI 70
Reeflex-io/reeflex

A seatbelt for the AI acting on your systems — deterministic, open-source governance gate for AI-agent actions

Python 0 AI 70 1 sig live ↗
0xsl1m/shadowshield

Unified open-source security shield for agentic AI systems — defense-in-depth prompt-injection protection (canary tokens, agent-trace alignment audit, tool-call guarding, PII/secret scanning).

Python 0 AI 70 Solo live ↗
joeyycli/constitution-lint-action

GitHub Action that lints CLAUDE.md-style agent constitution files for missing operational guardrails — spend limits, injection defense, escalation paths, secrets rules

Python 0 AI 60 Solo live ↗
siva010928/agnos-proxy-oss

Self-hosted, OpenAI-compatible AI gateway that splits your control plane (auth, guardrails, budgets, encrypted key vault, cost & observability) from the translation engine - swap Bifrost / LiteLLM / Portkey / Direct per provider at runtime. Own your keys; contain a compromised engine to one in-flight request.

Python 0 AI 60 Solo live ↗
Matik103/sanctum-runtime

Open-source trust layer for autonomous AI — gate agent, robot, smart home, and industrial actions before they run. Policies, HITL, Ollama/OpenAI, audit. MIT. npm @sanctum-runtime/sdk

TypeScript 0 AI 50 Solo 1 sig live ↗

RELATED Other topics · full topics ranking →

#claude-code

1,564

#ai-agents

1,160

#llm

1,071

#claude

943

#python

806

#ai

741

#developer-tools

728

#mcp

727

#codex

521

Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology