Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

AgentArmor

open-source 8-layer security framework for AI agents

Details

External ID
47374958
Source
HN
Company
—
Product
AgentArmor
Website domain
github.com
Launched
March 14, 2026
Cohort
—
Upvotes
10
Upvotes percentile
0.5781057810578106
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

I've been talking to founders building AI agents across fintech, devtools, and productivity – and almost none of them have any real security layer. Their agents read emails, call APIs, execute code, and write to databases with essentially no guardrails beyond "we trust the LLM."So I built AgentArmor: an open-source framework that wraps any agentic architecture with 8 independent security layers, each targeting a distinct attack surface in the agent's data flow.The 8 layers: L1 – Ingestion: prompt injection + jailbreak detection (20+ patterns, DAN, extraction attempts, Unicode steganography) L2 – Storage: AES-256-GCM encryption at rest + BLAKE3 integrity for vector DBs L3 – Context: instruction-data separation (like parameterized SQL, but for LLM context), canary tokens, prompt hardening L4 – Planning: action risk scoring (READ=1 → DELETE=7 → EXECUTE=8 → ADMIN=10), chain depth limits, bulk operation detection L5 – Execution: network egress control, per-action rate limiting, human approval gates with conditional rules L6 – Output: PII redaction via Microsoft Presidio + regex fallback L7 – Inter-agent: HMAC-SHA256 mutual auth, trust scoring, delegation depth limits, timestamp-bound replay prevention L8 – Identity: agent-native identity, JIT permissions, short-lived credentialsI tested it against all 10 OWASP ASI (Agentic Security Integrity) risks from the December 2025 spec. The red team suite is included in the repo.Works as: (a) a Python library you wrap around tool calls, (b) a FastAPI proxy server for framework-agnostic deployment, or (c) a CLI for scanning prompts in CI.Integrations included for: LangChain, OpenAI Agents SDK, MCP servers.I ran it live with a local Ollama agent (qwen2:7b) – you can watch it block a `database.delete` at L8 (permission check), redact PII from file content at L6, and kill a prompt injection at L1 before it ever reaches the model.GitHub: https://github.com/Agastya910/agentarmor PyPI: pip install agentarmor-coreWould love feedback, especially from people who have actually built production agents and hit security issues I haven't thought of.TAGS: security, python, llm, ai, agents

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Horizontal
Function
Compliance & governance
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
security framework for ai agents
Manually corrected
False

Could you build this?

Yes It is an open-source middleware library providing validation rules, prompt-injection regex/LLM checks, schema guards, and rate limiting around LLM agent function calls.

Discussion

6 comments analyzed.

Competitors mentioned: Network-AI coordination layer (open-source), Agent wrappers with input scanning

Concerns raised: Risk scoring only considers action verb, ignores parameters/targets, TrustScorer decay_rate not applied, dormant agents retain old trust scores, Race conditions when multiple agents write to shared context simultaneously, Inter-agent trust scoring in delegated actions and nested calls, Prompt injection attempts beyond red team suite

Feature requests: Param-aware risk rules in policy engine for target-sensitive actions, Time-based decay for trust scores in long-running multi-agent setups, Runtime trust evaluation adapting dynamically as agents interact in workflows, Cross-agent permission handling for dynamic workflows

Competitors

Other products that read as similar to this one — 696 launches clear the similarity bar, closest 8 shown.

Attention rank: #306 of 697 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 131 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.