A tool, a guardrail, a compliance check, an evaluator. Drops into any workspace in any runtime. The smallest unit of capability you can buy.
Filter by category. Click a card to see permissions, supported runtimes, changelog, and full description.
Real-time scanning against the OWASP Agentic Top 10 attack vectors. Blocks prompt injection, tool poisoning, and lateral A2A escalation before execution.
Auto-generates audit trails, transparency disclosures, and human oversight records mapped to specific EU AI Act articles. Export-ready PDF & JSON.
Refuses rm -rf, chmod 777, fork bombs, and 60+ destructive shell patterns. Hard block, no override.
Multi-dimensional review — security, performance, readability, test coverage, dependency hygiene, license compatibility, and 10 more.
Routes the same diff to Claude, GPT-5, and Gemini. Surfaces disagreements as review comments — consensus or escalation.
Blocks any agent from importing dependencies with known CVEs above your configured CVSS threshold. NIST + GHSA feeds.
Lock workspace filesystem access to declared paths. Anything outside throws EACCES at the runtime layer.
Tiered human approval — single reviewer, dual sign-off, or executive override. Routes by risk score and org topology.
Hourly memory consolidation. Promotes repeated successful patterns into Hermes skills. Set-and-forget.
Watches code diffs, regenerates the corresponding docs section, opens a PR. Keeps docs.* and src/* in lockstep.
Headless Chromium under HITL gating. Form fill, scrape, screenshot, PDF export — with a kill switch on every action.
Lint, type, test, coverage, security, license, signoff. Seven mandatory gates before any agent-authored PR can merge.
Redacts API keys, tokens, and PII from agent prompts and outputs. Pattern library updated nightly.
Streams every tool call as a Datadog span. Latency, error rate, and cost all flow into your existing dashboards.
Blocks GPL/AGPL contamination of proprietary code. Per-package allowlist. SPDX-compliant.
Two-key HITL — production diffs require two distinct human approvers. Enforces separation of duties.
Long-term memory with TTL, scoping, and decay. Drops in any agent; backed by pgvector.