Portfolio
Every project you're building, at a glance.
At a glance
44 reposLanguages
6 shown- TypeScript14
- Go7
- JavaScript5
- Python5
- Ruby1
- Shell1
Health
by activity- This week9
- This month20
- Stale11
- Dormant4
Visibility
public / private- Public43
- Archived1
Most active
219 commits / 30dBy workspace
1 shownDamn Vulnerable AI Agent is a deliberately vulnerable AI agent platform for security testing and education.
Multi-source analytics tracker for open-source projects. Preserves GitHub traffic beyond 14 days and aggregates npm, PyPI, and Docker download stats with a Next.js dashboard.
One command to keep secrets out of AI (LLMs). Works with Claude Code, Cursor, Copilot, Windsurf, and any AI coding tool.
Homebrew tap for OpenA2A CLI
Agent Authorization Protocol (AAP): scoped, attested authorization for AI agent systems. Token model + broker/resolution layer.
A firewall for browser agents. Chrome extension that detects, monitors, and controls AI agents in your browser. Identifies Playwright, Puppeteer, Selenium, Anthropic Computer Use, and OpenAI Operator without the agent identifying itself.
One scan for AI risk. `opena2a review` checks an AI project across credentials, shadow agents, MCP servers, and dependencies, returns a score, and routes each finding to the tool that fixes it. Open source.
Conformance fixtures and Node+Python reference verifiers for the Agent Authorization Protocol (AAP) token canonical form
The ai-safety.txt domain AI-safety declaration format (IETF Internet-Draft draft-fane-ai-safety-txt-00).
The IAM layer for AI agents: cryptographic identity, capability authorization, and audit trails for non-human identities. Open source.
Open Agent Security Benchmark - 222 attack scenarios, product-agnostic adapter interface, MITRE ATLAS mapped
AI Injection Signature Standard — YARA-style signatures for AI agent prompt injections in web content. Apache 2.0.
VirusTotal for AI packages. ai-trust check <pkg> returns a 0-100 trust score from the OpenA2A Registry trust graph, covering security scans, advisories, and dependency risk. For MCP servers, A2A agents, skills, and LLM packages.
Metasploit for AI agents: scan, attack, and fix AI agents and MCP servers. Open source security toolkit.
On-device models that detect and classify AI agent attacks. A 2M-param classifier (<1ms, offline) and a 1.7B-param analyst, shipping inside HackMyAgent, Secretless, and the OpenA2A CLI.
Security checklist and audit tools for MCP (Model Context Protocol) server deployments
did:opena2a DID method specification
Conformance fixtures and reference verifiers for ATX v1.0 (Agent Trust Credential).
Canonical conformance suite for A2A-IDF (Agent-to-Agent Identity Framework, a2aproject/A2A#1496). Verification levels, attestation envelopes, delegation chains, and cross-layer composition fixtures.
Scaffold for Agent Identity Protocol v1.0.0-draft conformance fixtures. Publicly surfaces the open architectural question on AIP fixture artifact shape. Sibling to atx-conformance and atp-conformance. Closes part (c) scaffolding of a2aproject/A2A#1885.
Conformance fixtures and reference verifiers for Agent Trust Protocol v1.0.0-rc1. Byte-stable JSON fixtures + Go (full hybrid Ed25519 + ML-DSA-65) and Python (Ed25519) verifiers. Closes criterion (c) of a2aproject/A2A#1885 for ATP.
OpenA2A Standards organization profile and community health files
Agent Behavioral Governance Specification (ABGS) - Behavioral safety framework for AI agents
AI Agent Threat Matrix: A structured framework for classifying, detecting, and defending against attacks on AI agent systems
OpenTelemetry semantic conventions for AI agent authorization observability.
Agent Identity Protocol (AIP) — an open standard for AI agent identity, capabilities, and trust
Fix comply() bare-string overload, AWS secret-key detection, scan help, bare decorators (#18)
The IAM layer for AI agents: cryptographic identity, capability authorization, and audit trails for non-human identities. Open source.
The IAM layer for AI agents: cryptographic identity, capability authorization, and audit trails for non-human identities. Open source.
Cross-CLI parity gate for the opena2a-org CLI fleet (hackmyagent, opena2a, ai-trust). Harness + fixtures + contract that proves byte-identical output across the fleet.
Agent Trust Protocol (ATP) — an open standard for verifiable trust assertions about AI agents
Open Agent Security Benchmark - 222 attack scenarios, product-agnostic adapter interface, MITRE ATLAS mapped
A curated collection of SOUL.md agent identity files. Security-focused, tool-agnostic, integrity-verified.
Agent Runtime Protection - runtime security monitoring for AI agents
Agent Trust eXtension (ATX) credential format and Agent Trust Protocol (ATP) architecture specifications. Open standard for AI agent trust credentials.
Agent Runtime Protection - runtime security monitoring for AI agents
GitHub Action that automatically adds and updates OpenA2A trust score badges in your README
GitHub Action: OpenA2A Registry trust gate for AI package dependencies
TypeScript SDK for A2A-IDF (Agent-to-Agent Identity Framework, a2aproject/A2A#1496). RFC 9421 + Ed25519 wire signatures, dual-shape keyid resolution, verification levels 0/1/2, attestation envelopes, delegation chains.
OpenA2A organization profile
One scan for AI risk. `opena2a review` checks an AI project across credentials, shadow agents, MCP servers, and dependencies, returns a score, and routes each finding to the tool that fixes it. Open source.
A firewall for browser agents. Chrome extension that detects, monitors, and controls AI agents in your browser. Identifies Playwright, Puppeteer, Selenium, Anthropic Computer Use, and OpenAI Operator without the agent identifying itself.
Example A2A agent implementations with security best practices and input validation