AI Dev Impact Lab JA
← Topics ranking · 2026-08
GITHUB TOPIC

#llm-security

GitHub repositories that have self-applied the topic "llm-security" — a creator-tagged metadata that surfaces how AI projects describe themselves.

32
tagged repos
55
top 32 stars
8
with tool sigs
32
shown

REPOS Repos for #llm-security (top 32 by stars)

mlcyclops/lucidagentide

Security-First Agentic IDE Coding Harness

TypeScript 15 AI 45 Solo 2 sig live ↗
NovaCode37/claude-security-skills

Production-ready Claude Code skills for cybersecurity — secret scanning, SAST, prompt-injection testing, HTTP/JWT/dependency auditing. Zero dependencies.

Python 11 AI 100
Actenon/actenon-scan

Find where agent-controlled intent reaches consequential actions without an authority check. Python + TypeScript + Go. Zero-dependency SAST for AI agents.

Python 4 AI 70
keynv-labs/keynv

Self-host secrets manager with an AI-safety layer. Aliases instead of values; AI agents never see real credentials. Cloud option coming.

TypeScript 3 AI 70 1 sig live ↗
prat3ik/evalbot

EvalBot — local-first chatbot security & quality evaluation (FastAPI + Next.js). Evaluate chatbot answers against your own docs & guidelines with ML/NLP + AI-judge scoring. Apache-2.0.

Python 3 AI 70
clay-good/proxilion

Proxilion is the security layer for the agentic workforce. It turns managed AI agents into governed users by enforcing strict cryptographic boundaries on every API call to SaaS like Google Workspace, Salesforce, or Atlassian.

Rust 3 AI 40 Solo live ↗
Krishita17/agent-memory-poisoning

Attack taxonomy, toolkit & defenses for persistent-memory poisoning of LLM agents. Author: Krishita Sanjay Choksi.

Python 2 AI 100
germankovacevic-lab/agent-audit-gate

An audit gate for AI agent outbound messaging: hold the draft, let a senior agent review it (no private-data leak, prompt-injection resistance), then release. Reference implementation.

TypeScript 2 AI 100
KezoSec/rag-poisoning-lab

A self-contained AI security lab demonstrating document poisoning, indirect prompt injection, and data exfiltration in RAG systems. Explores the "helpfulness paradox" across local and frontier LLMs.

Python 2 AI 100
Vadale/project-guardian

AI Guardian Firewall — a local, user-space, agent-agnostic firewall that mediates an autonomous AI agent's actions (files, shell, network, services) with a deterministic policy boundary, a tamper-evident audit log, and a human-in-the-loop approval cockpit. No kernel modules. Apache-2.0.

Rust 2 AI 70
woshilaohei/border-guard

Border Guard — AI-native territory sovereignty & self-evolving security OS. 6-module D-S fusion engine, trajectory detection, anchor detection, fission engine, territory adjudicator. Full design + Python implementation.

Python 2 AI 70 Solo 1 sig live ↗
mthamil107/ai-bot-shield

Drop-in middleware that detects AI bot traffic. Community-maintained signature database + RFC 9421 Web Bot Auth verification. Node + Python + Go. Apache-2.0.

Python 1 AI 100
BrendenKennedy/claude-for-ai-platforms

Claude Code scaffold for building AI platforms securely — agent/LLM security, Kubernetes, SRE, observability, identity, and supply chain, grounded in published framework canon (OWASP, NIST, CIS, SLSA). Data-science lanes included.

Shell 1 AI 100 1 sig
Niki-1337/proxy-ai

Open-source AI Security Gateway that sanitizes secrets, PII, and internal context before prompts reach external LLMs.

Rust 1 AI 100
HDHNezherParking-cum-Y638-Intl-Ltd/titan

A disciplined 10-stage autonomous agent pipeline (Reflexion, Tree Search, ReAct) for Claude Code and AI coding agents. Lifts local LLMs to senior engineering quality.

1 AI 70
guorunjie/agentic-workflow-guard

Static analysis for AI automation workflows. Find prompt-injection paths, overpowered tools, and write-capable agent jobs before they run.

JavaScript 1 AI 70 Solo 4 sig live ↗
hamodywe/promptfence

Static analysis for AI agents in GitHub Actions — finds where attacker-controlled text reaches an agent's prompt, and what that agent is allowed to do with it.

TypeScript 1 AI 60
MAUROCERON/ai-agent-security-mini-audit

Free AI-agent risk self-check, security checklist, and USD 59 launch-readiness mini-audit offer.

HTML 0 AI 100 Solo live ↗
SamsonCyber/llm-injection-field-guide

Dark Promptery: 324 LLM prompt-injection techniques, crosswalked to OWASP/MITRE ATLAS/NIST/CWE.

HTML 0 AI 100 Solo live ↗
perpensum/agent-directed-manipulation

A reproducible definition separating agent-directed manipulation from legitimate machine-readable self-presentation. Two mechanically decidable axes, 13 conformance cases.

HTML 0 AI 100 live ↗
roleplay-sh/ai-agent-social-engineering-research

Curated research on AI agent social engineering, manipulated delegation, prompt injection, tool-use boundaries, and agent security evaluation.

0 AI 100
Gowrav-M/agent-skillguard

Policy-as-code admission controller for AI agent skills and MCP tools. SkillBOM, lockfiles, and supply-chain baselines.

TypeScript 0 AI 100
ch040602/agent-prompt-injection-zoo

Source-backed archive of agent prompt-injection incidents, research records, trust-boundary patterns, schemas, and sanitized defensive summaries.

HTML 0 AI 100 Solo live ↗
Reeflex-io/reeflex

A seatbelt for the AI acting on your systems — deterministic, open-source governance gate for AI-agent actions

Python 0 AI 70 1 sig live ↗
Thomas-LEON/agentguard

🛡️ Experimental security guardrails for LangChain agent code execution (Alpha)

Python 0 AI 70
Builder106/halberd

A JSON-RPC firewall for MCP agents — inspects every tools/call between an LLM and its MCP servers, blocking argument injection and capability creep before they reach the host.

Go 0 AI 70 Solo live ↗
MasonNagel5/MCP-Security-Scanner

Controlled study measuring whether prompt-injection poison hidden in MCP tool descriptions actually changes an LLM's behavior.

Python 0 AI 70
0xsl1m/shadowshield

Unified open-source security shield for agentic AI systems — defense-in-depth prompt-injection protection (canary tokens, agent-trace alignment audit, tool-call guarding, PII/secret scanning).

Python 0 AI 70 Solo live ↗
SamsonCyber/agentic-dm-gateway

Hermes-inspired security control plane for LLM agents over private DMs: allowlist, PIN, kill switch, rate limits, injection heuristics, secret redaction, audit log.

Python 0 AI 70
Mithun-veerabuthiran/SSS-Secure-Shielding-Service

Privacy-first Chrome extension and Flask backend for protecting AI prompts through real-time PII detection, anonymization, pseudonymization, and redaction before sensitive data reaches AI services.

0 AI 70 Solo live ↗
rbardyla-boop/claude_powerplant

Trust-bounded acceptance harness for Claude coding agents — sanitized workspaces, typed tools, isolated oracle evaluation, evidence receipts.

TypeScript 0 AI 60 1 sig
Matik103/sanctum-runtime

Open-source trust layer for autonomous AI — gate agent, robot, smart home, and industrial actions before they run. Policies, HITL, Ollama/OpenAI, audit. MIT. npm @sanctum-runtime/sdk

TypeScript 0 AI 50 Solo 1 sig live ↗

RELATED Other topics · full topics ranking →

#claude-code

1,564

#ai-agents

1,160

#llm

1,071

#claude

943

#python

806

#ai

741

#developer-tools

728

#mcp

727

#codex

521

Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology