pydantic/monty
- Source
- GitHub
- First trending
- Category
- Security
- GitHub stars
- 8,233
- Main language
- Rust
This page introduces an external open-source repository. It is not an HDATF product.

What it does
A sandboxed Python interpreter written in Rust for running AI-written code without a container or VM. Code reaches the host only through functions and mounts passed in, and the interpreter enforces memory, time and recursion limits.
How it helps ATF
A reference for how Harness could let an agent run code with no access to files, network or environment variables unless a host function allows it. Worth comparing with container-based sandboxes.
License
MIT Permissive. Commercial use and changes are allowed if the copyright notice is kept.
More in this category
- KeygraphHQ/shannon
An AI agent that tests web applications and APIs for security flaws. It reads the source code, finds attack paths and runs real exploits, reporting only vulnerabilities it can prove, with CI/CD runs and SARIF output. - lissy93/web-check
Web-Check is a dashboard that gathers public information about a website, such as IP details, SSL chain, DNS records, cookies, headers, open ports, trackers and redirects. It can be self-hosted, for example with Docker. - QuipNetwork/hashsigs-rs
A Rust workspace of hash-based post-quantum signature schemes, including WOTS+, SPHINCS+C and the hybrid SHRINCS signer and verifier. It also includes WebAssembly bindings and a verify-only Solana program. - gommzystudio/device-activity-tracker
A security research proof-of-concept based on a University of Vienna and SBA Research paper. It measures the round-trip time of WhatsApp and Signal delivery receipts to infer whether a device is active, in standby or offline. - vxcontrol/pentagi
An autonomous AI agent system that carries out penetration testing tasks. It works with several LLM providers and includes agent supervision, Langfuse integration and a Graphiti knowledge graph.
Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.