{"repo":"garagon/aguara","free":true,"listed":false,"github":"https://github.com/garagon/aguara","clone":"git clone https://github.com/garagon/aguara.git","description":"The open source security engine for AI agent and supply-chain trust.","language":"Go","stars":86,"topics":["ai-agents","mcp","prompt-injection","security","devsecops","supply-chain-security","github-actions","npm","pnpm","pypi"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"Aguara Open source security engine for AI agent and supply-chain trust. Run it before install, before CI, or before handing a repo to an AI coding agent. Aguara checks packages, lockfiles, install scripts, package-manager policy, MCP configs, CI workflows, agent settings, and instruction files locally and deterministically. Why Aguara &bull; When to use it &bull; What it checks &bull; Quick Start &bull; Before install / delegation / CI &bull; Threat intel &bull; Behavioral detection &bull; CI adoption &bull; Install https://github.com/user-attachments/assets/851333be-048f-48fa-aaf3-f8cc1d4aa594 No SaaS account. No telemetry. No LLM calls. Signed releases. Signed threat intel. - Runs locally — your code, prompts, configs, and dependency data never leave the machine. - No telemetry — nothing is phoned home. - No LLM calls — deterministic static analysis, same input gives the same result. - Signed threat intel — an embedded snapshot ships in the binary; fresh updates are signed and opt-in. Why Aguara Modern software does not only run your code. It runs package install scripts, lockfile-resolved dependencies, CI workflows, MCP servers, agent skills, and tool configs. Aguara checks those trust points before they execute or become part of your workflow. The recurring supply-chain pattern is simple: a legitimate package publishes a malicious version, a project installs it, and the install-time code steals tokens, cloud credentials, CI secrets, or local files. The same risk now exten","default_branch":null,"files":null,"tree":[],"storefront":"/r/garagon","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/garagon/aguara/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}