astrid-runtime/astrid
- Source
- GitHub
- First trending
- Category
- Security
- GitHub stars
- 10,276
- Main language
- Rust
This page introduces an external open-source repository. It is not an HDATF product.

What it does
A portable runtime, heading toward a standalone operating system, that runs WebAssembly capsules in a sandbox on macOS and Linux. Capsules talk through typed interfaces, and file, network, process and IPC access is checked at runtime boundaries.
How it helps ATF
Its principle that a model chooses actions but does not grant permission is worth comparing with keeping the ATF Works assistant within each person's permissions. It could also be a reference for scoping what Harness executors can access.
License
Apache-2.0 Permissive, with a patent grant. Commercial use is allowed; keep the notices and state your changes.
More in this category
- usestrix/strix
Strix runs AI agents that test an application the way attackers would: they execute the code, look for vulnerabilities and confirm them with working proofs of concept. It offers a CLI, multi-agent orchestration, suggested patches, reports and CI/CD use. - astrid-runtime/book
The canonical reference book for Astrid, built with mdBook, covering the kernel, the capsule model, the host ABI, the bus and the security model. Appendices such as the capability catalog are generated from the Astrid source. - openai/codex-security
Codex Security is a CLI and TypeScript SDK from OpenAI for defining security policy and for finding, validating and fixing vulnerabilities in code. It can also draft a SECURITY.md to guide later scans. - simplex-chat/simplex-chat
SimpleX Chat is a messaging network with apps for iOS, Android and desktop that works without user identifiers of any kind, aiming to keep communication private by design. - guillaumemeyer/watermarks-remover
An agent skill plus a Python service that strips AI provenance marks from content you own, such as invisible Unicode characters, statistical text watermarks and C2PA, EXIF or XMP metadata in files. The skill calls the service over HTTP.
Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.