archestra-ai/OpenAPPA

Source
GitHub
First trending
Category
Security
GitHub stars
1,247
Main language
Rust
Website
openappa.com (opens in a new tab)

This page introduces an external open-source repository. It is not an HDATF product.

archestra-ai/OpenAPPA

What it does

A guardrail that sits between an agent and its tools and answers one question before every action, whether this data is allowed to go to this destination. It tracks the sensitivity and trust of everything the agent reads and checks each tool call against that record before the call runs. Policy is declarative TOML, and the engine decides from the event log alone and makes no network or file calls, so the same log always gets the same decision. It runs in process or as a sidecar process.

How it helps ATF

Harness runs AI work that reads our own material and then calls outside tools, and whether a given piece of that material may leave is exactly the question to settle before the call. A check written as policy that returns the same answer for the same log is worth comparing with the rules we write around Harness.

License

MIT Permissive. Commercial use and changes are allowed if the copyright notice is kept.

More in this category

  • ThinkWatchProject/ThinkWatch-Lite
    A local gateway placed in front of Claude Code, Codex and other AI clients on macOS, Windows and Linux. Each client is pointed at the gateway once, after which upstreams and models change without touching client configuration. Every request is recorded with its cost and route, API keys and other secrets can be replaced before a request leaves the machine, and a dangerous tool call that a relay slips into an answer can be cut off before the client runs it.
  • mvt-project/mvt
    A mobile forensic toolkit for collecting traces of possible Android and iOS compromise and checking public indicators of compromise. It is intended for investigators with forensic expertise, not end-user self-assessment.
  • OffGridPete/Fieldwatch
    A receive only Wi-Fi and Bluetooth LE observer for Android. The author describes it as passive, listening only, with no dongle, no account and no backend server, built to work offline in the field. It offers a filtering engine, an extensible signature library for identifying radio sources, and reports of what was seen, and everything stays on the phone.
  • hwdsl2/wireguard-install
    A WireGuard VPN server installer for several Linux distributions. It supports automated or interactive setup, client profile and QR code generation, user management, and IPv4 and IPv6 clients.
  • scadastrangelove/awesome-ai-security-tools
    A curated catalog of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity. Topics include agent security, supply-chain security, scanners, runtime protection, and evaluation frameworks.

Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.

View on GitHub (opens in a new tab)