cosmian_cover_crypt
Key Policy attribute encryption based on subset cover
alint
Language-agnostic linter for repository structure, file existence, filename conventions, and file content rules
sqlx-adapter
Sqlx adapter for casbin-rs
apl-core
APL — Authorization Policy Language core (compiler + evaluator)
nym-exit-policy
Get and set the Nym Exit Policy, used by Exit Gateways
codewandler-flux-policy
flux pure authorization: default-deny grant evaluation with trust levels, scopes, and wildcard/path matching
google-policytroubleshooter1
A complete library to interact with Policy Troubleshooter (protocol v1)
apl-cmf
APL ↔ CPEX bridge — extension → AttributeBag mapping
pdfv
Command-line interface for the pdfv validator
fitctl
CLI for host survey, contract derivation, and workload-fit validation
google-policytroubleshooter1-cli
A complete library to interact with Policy Troubleshooter (protocol v1)
modum
Workspace lint tool for Rust naming and API-shape policy
repoctl-engine
Discovery, graph construction, and policy evaluation services for repoctl
wkd-server
A WKD server
heimdall-linux-sandbox
Linux sandbox backend for Heimdall using bubblewrap and namespaces
heimdall-sandbox-policy
Policy document types and filesystem policy materialization for Heimdall
vellaveto-proxy
MCP stdio proxy with built-in security presets — zero config needed
assay-policy
Policy types and compilation logic for Assay
vellaveto-types
Core type definitions for Vellaveto policy engine
vellaveto-tls
Shared TLS/mTLS module for Vellaveto server and HTTP proxy
repl-core
Core REPL engine for the Symbi platform
directiva
A tiny, paste-friendly directive mini-language: ACTION:[<KIND>]NAME[@PATH][=NOTE]
heimdall-core
Core Heimdall sandbox runtime orchestration and execution types
aranya-idam-ffi
The IDAM FFI for Aranya Policy
heimdall-sandbox
Process sandbox runtime for Heimdall
vellaveto-shield
Consumer AI shield: bidirectional PII sanitization with encrypted local audit
gatekeep
Code-first authorization engine for Rust
aranya-crypto-ffi
The crypto FFI for Aranya Policy
signet-eval
Deterministic authorization for AI agent tool calls
tyrant
A Cobra-style lexeme policy engine: write declarative rules over a codebase's tokens and enforce them in a pre-commit hook, CI gate, or agent loop
roder-tui
Agentic software development tools and SDKs for Roder
aranya-policy-compiler
The Aranya Policy Compiler
nmp-cli
NMP developer CLI: scaffold apps as explicit owner-crate composition shells, install app-owned components, and inspect/upgrade the NMP dependency policy
aranya-envelope-ffi
The envelope FFI for Aranya Policy
aranya-policy-module
The Aranya Policy module format
aranya-perspective-ffi
The perspective FFI for Aranya Policy
denyx-cli
Denyx CLI: run a policy-gated Starlark script with default-deny capability enforcement
perspt-policy
Starlark execution policy engine for Perspt
aa-sandbox
WebAssembly/WASI sandbox runtime for Agent Assembly tool execution
aranya-capi-core
Aranya's C API tooling
antissrf
Microsoft AntiSSRF
aranya-device-ffi
The device FFI for Aranya Policy
sbo3l-policy
SBO3L policy engine: YAML/JSON policy parsing + rule evaluation + persistent budget tracking
cedar-policy-cli
CLI interface for the Cedar Policy language
aranya-policy-vm
The Aranya Policy Virtual Machine
diesel-adapter
Diesel adapter for casbin-rs
creditlint
CLI for enforcing Git credit and authorship metadata policy
agentzero-core
AgentZero — modular AI-agent runtime and tool framework
vigil-policy
Policy engine for Vigil — declarative ALLOW/DENY rules, OAuth scope allowlist DSL, capability levels
zerodds-qos
DDS QoS policies (DDS 1.4 §2.2.3) + Request/Offered Compatibility-Matrix + PL_CDR_LE PID-Wire-Codec (DDSI-RTPS §9.6.3.2). Pure-Rust no_std + alloc.
tyrant-token
The lexeme/token model for tyrant
openvet-policy
Requirement language and Kleene evaluator for OpenVet audit policies
cpex
CPEX host facade — re-exports the runtime and (optionally) the feature-gated builtin extensions
stateset-policy
Declarative policy engine for StateSet iCommerce — conditions, rules, deny-overrides, and explainable denials
agent-shell-parser
Shared parsing substrate for agent hook binaries — JSON input, shell tokenization
cedar-policy-validator
Validator for the Cedar Policy language
aranya-client
Client library for using Aranya
torg-core
TØR-G: Token-Only Reasoner (Graph) - Boolean circuit IR for AI policy synthesis
kastellan-core
Agent core: scheduler, memory orchestration, policy gate, LLM router, IPC, audit log
sbo3l-server
SBO3L HTTP daemon: POST /v1/payment-requests pipeline (auth, idempotency, policy, budget, audit, signed receipt)
cellos-cortex
Bridge between CellOS execution cells and the Cortex doctrine layer — DoctrineAuthorityPolicy, CortexCellRunner, CellosLedgerEmitter
platonic-core
Core Rust harness primitives for disciplined, replayable agent execution
sbo3l-storage
SBO3L storage: SQLite persistence + hash-chained audit log
aranya-crypto
The Aranya Cryptography Engine
tyrant-frontends
Language frontends that lex source into token streams for tyrant
allow-policy
Policy parsing and validation for cargo-allow source exception ledgers
ai-lib-contact
AI-Protocol policy layer: cache, batch, routing, plugins, resilience, guardrails, tokens, telemetry
helix-evidence
ADR-006: evidence tiering and explicit abstention policy for Helix
defect-sandbox
Sandboxing and command execution policy primitives for the defect agent
cedar-policy-formatter
Policy formatter for the Cedar Policy Language
roder-edit-core
Agentic software development tools and SDKs for Roder
tyrant-report
Violation reporting (human, JSON, agent) for tyrant
tessellate
Command-line interface for the Tess rule language
apl-cpex
APL ↔ CPEX runtime bridge — per-hook PluginInvoker implementations
agntcy-shadi-cli
Command-line interface for SHADI policy, secrets, memory, and SLIM operations
vellaveto-approval
Human-in-the-loop approval workflow with deduplication
sc-lint
Top-level CLI composition root for the sc-lint tool family
converge-soter-smt
SMT-backed safety and policy assurance suggestors for Converge
cedar-local-agent
Foundational library for creating Cedar-based asynchronous authorizers
gommage-stdlib
Bundled policy and capability mapper stdlib for Gommage
vellaveto-discovery
MCP tool topology crawling and verification for VellaVeto
aranya-id
Aranya ID types
denyx-mcp
Denyx MCP server: exposes the policy-gated Starlark host over stdio JSON-RPC for Claude Code, opencode, and other MCP clients
clawdstrike
Security guards and policy engine for AI agent execution
treetop-core
Core library for Treetop, a Cedar policy engine implementation
deepseek-execpolicy
Execution policy and approval model parity for DeepSeek workspace architecture
gatekeep-axum
Axum integration adapter for gatekeep
allow-diff
Source-tree and policy posture diff helpers for cargo-allow
restrict
allow, deny, or trace Linux syscalls with an ergonomic, auto-generated enum customized for your system architecture
vellaveto-cluster
Distributed state backend for Vellaveto clustering (Redis or local)
sbo3l-mcp
SBO3L MCP — stdio JSON-RPC server wrapping SBO3L primitives (validate_aprp, decide, run_guarded_execution, verify_capsule, audit_lookup, explain_denial)
winit-appkit
Winit's Appkit / macOS backend
grapheme-runtime
Policy-governed Grapheme runtime engine
gam-runtime
Resource policy, caching, and warm-start runtime foundation for the gam penalized-likelihood engine
vigil-firewall
Fail-closed effect firewall for Vigil — policy engine, approval queue, PII scanner, OAuth scope allowlist
torg-mask
LLM logit masking for TØR-G constrained decoding
vellaveto-http-proxy
Vellaveto MCP policy firewall — Streamable HTTP reverse proxy
amiss-scan
Discovery, reference resolution, correlation, evaluation, and policy for Amiss
cpex-pdp-cedar-direct
CPEX PDP — Amazon Cedar policy evaluation
allow-files
Non-Rust and generated-file scanners for cargo-allow source-tree policy
kcr_policy_kubeedge_io
Kubernetes Custom Resource Bindings
firewall-objects
Firewall object primitives for networks, services, and application indicators
typesec-cli
CLI for typesec — validate, check, generate, run
cpex-plugin-identity-jwt
CPEX identity handler — JWT validation and claim mapping
cpex-pdp-cel
CPEX PDP — CEL (Common Expression Language) predicate evaluation
ainl-contracts
Shared policy contracts for repo intelligence, context freshness, and impact-first tooling (no OpenFang deps)
policycheck
Publisher policy compliance checker - verifies robots.txt, RSL licenses, Content Signals, and TDM policies
latch-retry
Retry, fallback and circuit-breaker policy primitives for Latch
fiat
A minimal Rust agent runtime for building custom AI agents
sbo3l-keeperhub-adapter
SBO3L adapter for KeeperHub workflow execution: signed PolicyReceipt + IP-1 sbo3l_* envelope, GuardedExecutor trait, mock + live constructors. See repo for the IP-1..IP-5 catalogue.
vellaveto-mcp-shield
Consumer shield: bidirectional PII sanitization, session isolation, encrypted local audit
omena-checker
Checker rule registry and diagnostic policy boundary for Omena
hushspec
Portable specification types for AI agent security rules
allow-inventory
Source-tree root discovery and file inventory for cargo-allow
tokenfold-learn
Policy-learning proposals for tokenfold compression reports
cpex-orchestration
Async concurrency primitives shared by the CPEX runtime
heimdall-macos-sandbox
macOS Seatbelt sandbox backend for Heimdall
ferrify-domain
Ferrify domain types for policy, planning, provenance, and reporting
nexara-cli
Command-line tools for Nexara policy authoring and demos
cpex-plugin-audit-logger
CPEX CMF plugin — structured per-request audit logging
vellaveto-canonical
Canonical security policy presets for common scenarios
cargo-scirs2-policy
Policy linter for SciRS2 workspace compliance
core-policy
Pure RBAC/ABAC policy engine core (zero crypto/network dependencies)
cpex-session-valkey
CPEX session store — Valkey/Redis-backed distributed session labels
aranya-afc-util
using Aranya Fast Channels
vellaveto-audit
Tamper-evident audit logging with hash chains and Ed25519 checkpoints
blackwall-cli
CLI for the Blackwall Protocol — type
blackwalland you’re protected
agent-rules
Convention and validation for prescribed policy in AI agent instruction files
vellaveto-http-proxy-shield
Consumer shield HTTP proxy layer with traffic padding and header stripping
vellaveto-mcp
MCP protocol security: DLP, injection detection, tool registry, and guardrails
aranya-fast-channels
High throughput, low latency encryption protected by Aranya Policy
cpex-plugin-pii-scanner
CPEX CMF plugin — detects and redacts PII (SSN, credit card, email) in tool/prompt args
runx-core
Pure Rust parity kernel for runx state-machine and policy decisions
roder-ext-chrome
Agentic software development tools and SDKs for Roder
rpsl-rs
A Routing Policy Specification Language (RPSL) parser with a focus on speed and correctness
uv-auth
internal component crate of uv
tiny_lfu
cache admission control policy
cpex-plugin-delegator-biscuit
CPEX delegation handler — Biscuit capability-token attenuation
perl-lsp-feature-policy
Policy and profile helpers for LSP capability selection
gatecheck
CLI leaf crate for gatecheck
oidfed_metadata_policy
To merge and resolve and apply OpenID Federation metadata policy
uv-client
internal component crate of uv
agent-safe-spl
SPL (Safe Policy Lisp) evaluator for Agent-Safe capability tokens. 150 lines, zero deps core, microseconds.
claw-guard
Security, session, and policy engine for ClawDB
vellaveto-server
Vellaveto policy engine — CLI and HTTP server
uv-torch
internal component crate of uv
sokr-dispatch-first
First-capable dispatch policy for SOKR substrate selection
torg-serde
Serialization/deserialization for TØR-G token streams
ferrumdeck
deterministic, in-path enforcement engine for AI agents — deny-by-default tool policy, Airlock RASP, the R1-R3 reversibility ladder, and an EU AI Act Art.50 transparency rule. Umbrella…
uv-requirements
internal component crate of uv
greentic-secrets-runner
Host bridge for environment-backed secrets with tenant policy enforcement
bamboo-notification
Notification policy (event classification, preferences, dedup) for the Bamboo agent framework
act-policy
Capability policy decision core (PDP) for the ACT toolchain
uv-cache
internal component crate of uv
retry-policy
Retry Policy
agent-policy
Schema-first generator for coding-agent repo policies and compatibility files
app-utils
modules for application logic (YAML, audit, timestamps)
clash_starlark
Starlark policy evaluator for Clash — compiles .star files to JSON policy
quantum-sign
post-quantum signatures, format, policy, and CLI in one crate
rskit-authz
RBAC and ABAC authorization engine
vellaveto-operator
Kubernetes operator for Vellaveto — manages VellavetoCluster, VellavetoPolicy, and VellavetoTenant CRDs
ty_python_semantic
internal component crate of Ruff
denyx-policy
Denyx policy types and runtime-parsed policy file format. Default-deny capability gates for AI-agent runtimes.
tokmd-gate
Policy evaluation engine for tokmd analysis receipts
cpex-plugin-delegator-oauth
CPEX delegation handler — RFC 8693 OAuth 2.0 token exchange
agntcy-shadi-sandbox
OS-level sandbox policy and process launching for SHADI
prep
Prepare Rust projects for greatness
uv-types
internal component crate of uv
cpex-sdk
CPEX plugin author SDK — Plugin trait, payloads, and result types
body
Policy-managed body lifecycle primitives for Rust systems
cpex-builtins
CPEX built-in plugins, PDPs, and session stores with feature-gated registration
aauth-httpsig-policy
Independent, fail-closed verification policy for HTTP Message Signatures
bss-oss-pcf-nextgen
Cloud-native 5G PCF: SBA-style policy edge, intent engine, closed-loop control, digital twin simulation, Policy-as-a-Service, and CHF-ready monetization
nostr-pubsub-social-graph
Social graph policy adapter for nostr-pubsub
awsim-efs
Amazon EFS emulator for AWSim
uv-version
internal component crate of uv
rust-toolkit-trait-contracts
Reusable trait contract support types for the rust-toolkit policy framework
uv-small-str
internal component crate of uv
uv-redacted
internal component crate of uv
libfse
Fused Semantic Execution: fail-closed policy engine with O(1)-in-rule-count scanning, zero-allocation hot path, and guaranteed enforcement semantics
relay-core-api
[Internal] Shared data contracts for relay-core. Use
relay-core-runtimeinstead.
uv-toml
internal component crate of uv
auths-policy
Policy expression engine for Auths - composable authorization logic
karu
An embeddable policy engine focusing on structural pattern matching over arbitrary JSON data
cf-mini-chat-sdk
SDK for mini-chat: policy plugin traits, models, and errors
vellaveto-canary
Warrant canary creation and cryptographic verification
rein-lang
A declarative language and runtime for AI agent orchestration
aclneko
caitsith policy abstract
awsim-kms
AWS KMS emulator for AWSim
ta-policy
Capability manifests and policy evaluation for Trusted Autonomy
aqc-filetree
Walk one directory root into a FileTree: gitignore-aware phase 1 plus rule-driven recovery phase 2
arcanum-agile
Cryptographic agility framework for the Arcanum cryptographic engine
forge-policy
Workspace and database safety policy primitives for forge-engine
ingress-policy
Deterministic policy primitives for Gatewarden
sekuire
The official SDK for the Sekuire Agent Identity Protocol
cedrus
REST API server for Cedar Policy
duende-policy
Policy enforcement for Duende (quality gates, circuit breakers, resource limits)
awsim-organizations
AWS Organizations emulator for AWSim
licensebat-cli
CLI tool to manage dependencies' license validation
shakrs-clippy-strict-policy
Shakrs strict Clippy policy: emits the baseline lint set and MSRV settings for Clippy configuration
reifydb-engine
Query execution and processing engine for ReifyDB
uaicp-core
UAICP Core Types and Traits — Rust Primitives
nexara-learning-jsonl
JSONL usage signal store for Nexara learning
nexara-learning-sled
Sled usage signal store for Nexara learning
firkin-admission
Admission control and capacity policy primitives for the firkin Rust containerization library
nexara-learning
Optional learned usage signal scoring for Nexara brokers
shakrs-hooks-policy
Shakrs policy for repo-level Git hooks setup
nexara
Policy-bound capability and tool runtime for AI systems
shakrs-rustc-strict-policy
Strict rustc lint table policy: the [workspace.lints.rust] seven-entry set
shakrs-toolchain-policy
Shakrs toolchain policy: coordinates rust-toolchain.toml and optional Cargo rust-version
deepmerge
Deep merge functionality with policy-driven merging and derive macro support
shakrs-rustfmt-policy
Shakrs rustfmt policy: coordinates Cargo edition and rustfmt.toml baseline settings
shakrs-deny-policy
Shakrs deny policy: emits the cargo-deny baseline configuration requirement
shakrs-cargo-policy
Shakrs Cargo baseline policy: requires the [lints] workspace opt-in so workspace lint tables apply
clash-lsp
lsp for clash policy files
olai-cedar-oci
Cedar policy provider backed by OCI-distributed policy bundles, with generated hydrofoil.policy gRPC types
ubl-wasm
UBL Chip execution engine for WebAssembly - BLAKE3 + JSON Atomic + Decision CID
nexara-remote
Remote tool discovery and execution contracts for Nexara
reovim-module-vim
Vim policy module for reovim - keybindings and behavior
bss-oss-pcf
Policy Control Function (PCF/PCRF) for 3G/4G/5G/6G networks - Policy Control, Charging Rules, and Quota Management with Diameter protocol support
ferrumdeck-policy
FerrumDeck enforcement engine: deny-by-default tool allowlists, Airlock RASP, the R1-R3 reversibility ladder, budgets, and an EU AI Act Art.50 transparency rule
g3rs-rustfmt-policy
g3 rustfmt policy: coordinates Cargo edition and rustfmt.toml baseline settings
txgate-policy
Policy engine for transaction approval rules in TxGate
g3rs-clippy-strict-policy
g3 strict clippy policy: bakes the legacy guardrail3 lint set + msrv into a ClippyLinterAdapterRequirement
nexara-compat-qwen
Qwen-family compatibility helpers for Nexara
g3rs-cargo-policy
g3 cargo baseline policy: requires the [lints] workspace opt-in so the workspace lint tables actually apply
ainl-context-freshness
Context freshness evaluation for conservative agent policy
covguard-domain
Pure policy evaluation engine for diff-scoped coverage decisions
g3rs-rustc-strict-policy
Strict rustc lint table policy: the [workspace.lints.rust] seven-entry set
torg-verify
Formal verification for TØR-G boolean circuits
conda_curation
Reduce conda repodata to enforce policy and speed up solves. Alpha software.
uv-dispatch
internal component crate of uv
ainl-impact-policy
Impact-first recommended tool sequences for AINL authoring
nexara-secrets
Secret store contracts and local encrypted secret storage for Nexara
rust-toolkit-effects
Effect support traits and marker types for the rust-toolkit policy framework
aios-kernel
Kernel orchestration layer for the Agent OS — tick lifecycle, agent loop, and composite runtime
chip_as_code
Semantic Chips — deterministic boolean circuits as text DNA. Parse, evaluate, evolve, and prove policy gates with No-Guess constitutional checkpoints.
rok-bouncer
Bouncer-style abilities and Policy authorization for the rok ecosystem
hushspec-cli
CLI tool for validating, testing, and scaffolding HushSpec policies
phenotype-casbin-wrapper
Casbin adapter providing policy enforcement for the Phenotype ecosystem
covguard-policy
Shared policy and profile contracts for covguard
tool-retry-policy
Declarative retry policy for LLM tool calls: per-tool max-attempts, exponential backoff, jitter, retriable-error filter. Returns a sleep duration; you run the call. Zero deps.
keypost-wrapper
Lightweight wrapper for local stdio MCP servers with Keypost policy enforcement
Try searching with DuckDuckGo.