Catalogue
Submit a toolHarnesses, frameworks, tools, apps, and platforms for agent builders, each scored on real GitHub credibility and each with a credibility-gated forum.
90 tools · showing 1–24
Deno
DeploymentSecurity
denoland
JavaScript/TypeScript runtime with capability-based permissions, used to sandbox agent-executed code and tools.
sandboxpermissionv8browser
SkillSpector
Security
NVIDIA
Security scanner that checks AI agent skills for vulnerabilities, malicious patterns, and supply-chain risks before install
static-analysisvulnerability-scannersupply-chainprompt-injection
OpenAI Agents SDK
CodingVoiceSecurity
openai
Python framework for multi-agent workflows with handoffs, guardrails, sessions, sandbox and voice agents, and built-in tracing
multi-agentguardrailsobservabilitysandbox
ToolOpenLIT
MonitoringSecurity
openlit
Open-source AI engineering platform with OpenTelemetry-native LLM observability, evaluations, and prompt management
telemetryevaluationpromptguardrails
AI-Infra-Guard
Security
Tencent
AI red-teaming platform for scanning agents, skills, MCP servers, and infrastructure and evaluating LLM jailbreaks
red-teamprompt-injectionjailbreak-testingvulnerability-scanner
Omnigent
CodingSecurity
omnigent-ai
Open-source meta-harness that orchestrates Claude Code, Codex, Cursor, and custom agents behind one interface with policies and sandboxing
codexmulti-agentgovernancesandbox
OpenShell
SecurityDeployment
NVIDIA
Sandboxed runtime for autonomous agents, with declarative YAML policies enforced at the HTTP method and path level
sandboxnetwork-policydockermicrovm
ToolBetter Auth
Security
better-auth
Agent Auth Protocol scopes agent identities and capabilities. Framework-agnostic.
authoauthmulti-tenancyagent-auth
ToolGiskard
QASecurity
Giskard-AI
Python library for testing agentic systems — evals with LLM-as-judge checks, red-teaming scans, and RAG quality evaluation
red-teamevaluationragprompt-injection
ToolJarvis Registry
ConnectorsSecurityMonitoring
ascending-llc
MCP and A2A gateway giving copilots and agents governed access to internal tools, with identity, access control, and observability
a2aoauthgatewayauth
PlatformPomerium
Security
pomerium
Open-source identity-aware reverse proxy that puts policy-based authn/authz in front of apps, agents and MCP servers.
zero-trustproxyidentity-awaregovernance
PlatformE2B
CodingSecurity
e2b-dev
Runs AI-generated code in isolated cloud sandboxes controlled from JavaScript or Python SDKs
sandboxcode-interpreterfirecrackercloud
ECC
CodingSecurityMemory
affaan-m
The agent harness performance optimization system. Coordinated engineering system and toolbox.
productivityskillvulnerability-scannergithubrollout
TooliFixAi
MonitoringSecurity
ifixai-ai
Catch your AI's mistakes and blind spots before your customers or regulators do..
governancered-teamevaluationcli
ToolPromptfoo
QASecurity
promptfoo
CLI and library for evaluating and red-teaming LLM apps, with side-by-side model comparison and CI/CD checks
eval-harnessred-teamci-cdvulnerability-scanner
OpenBot
InterfaceSecurity
CopilotKit
Open-source AI coworkers that each get a computer of their own: a browser, files and tools, with every action decided before it happens and
ag-uicopilotkitgenerative-uihuman-in-the-loop
ToolSnyk Agent Scan
Security
snyk
Security scanner for AI agents, MCP servers and agent skills.
prompt-injectiontool-poisoningvulnerability-scannersupply-chain
ToolArcjet
Security
arcjet
JS/TS security SDK: bot and AI-crawler detection, rate limiting, PII and prompt-injection checks for AI apps.
sdkprompt-injectionbot-detectiongateway
HarnessNanoClaw
SecurityConnectors
nanocoai
Personal AI assistant that runs agents in isolated Docker containers, kept to a codebase small enough to read and fork
dockersandboxlocal-firsttelegram
ToolShannon
Security
KeygraphHQ
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and
penetration-testingred-teamvulnerability-scannerbrowser-automation
FrameworkBAML
Security
BoundaryML
BAML (Basically A Made-up Language) is the programming language for agents.
dslstructured-outputtype-safetytool-calling
Garak
Security
NVIDIA
Command-line vulnerability scanner that probes LLMs for jailbreaks, prompt injection, data leakage, toxicity, and other failures
red-teamprompt-injectionvulnerability-scannercli
ToolInspector
CodingDeploymentSecurity
MCPJam
Development and testing platform to debug, chat with, inspect, and run evals against MCP servers, MCP apps, and ChatGPT apps
oauthevaluationdebuggingobservability
ToolPinchTab
InterfaceSecurity
pinchtab
I've been comparing ways to give agents web access, and what sets PinchTab apart is a security boundary. It drives real
browser-automationstealthmulti-instancegui