{"repo":"Mindburn-Labs/helm-ai-kernel","free":true,"listed":false,"github":"https://github.com/Mindburn-Labs/helm-ai-kernel","clone":"git clone https://github.com/Mindburn-Labs/helm-ai-kernel.git","description":"Fail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.","language":"Go","stars":56,"topics":["ai-agents","ai-security","developer-tools","llm-security","mcp","model-context-protocol","self-hosted","zero-trust","agent-security","evidencepack"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"HELM AI Kernel A local firewall for AI-agent actions. HELM sits between Claude Code, Codex, MCP tools, shell commands, and other agent actions. It decides ALLOW , DENY , or ESCALATE , then writes a signed receipt you can verify later. Verification checks signature integrity out of the box; trusting who signed is a separate, explicit step — see local signer and trusted verification. Try It Ask your agent to do something risky. HELM blocks or escalates the action before it runs, then records the decision. This proves the receipt was not altered ( integrity valid ). Signer trust is a separate verdict ( signer trusted ), evaluated against an expected workstation public key — by default the one in your local --data-dir ; for receipts copied from another machine, pin the signer's key out of band with --trusted-public-key-file . Receipts signed by the legacy derivable seed (retired in the security patch line) always remain untrusted. No cloud account. No model key. No Docker. No production credentials. What It Does Agent tries to... HELM does this Proof --- --- --- Run a destructive shell command¹ DENY signed receipt Use an unknown MCP tool ESCALATE quarantine record Read protected secrets DENY fail-closed receipt Run approved work ALLOW receipt + evidence Export a review bundle verify offline EvidencePack ¹ The hook's shell guard matches an intentionally narrow set of destructive command patterns — it is not a general shell analyzer. See the guard's scope. HELM only governs effects","default_branch":null,"files":null,"tree":[],"storefront":"/r/Mindburn-Labs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Mindburn-Labs/helm-ai-kernel/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}