{"repo":"makerchecker/MakerChecker","free":true,"listed":false,"github":"https://github.com/makerchecker/MakerChecker","clone":"git clone https://github.com/makerchecker/MakerChecker.git","description":"Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of duties, and cryptographically signed, offline-verifiable audit logs.","language":"TypeScript","stars":51,"topics":["ai-agents","langchain","mcp","agentic-ai","audit-trails","cryptography","governance","llm-security","open-source","role-based-access-control"],"license":"AGPL-3.0","category":"ai-agents","readme_excerpt":"🛡️ MakerChecker The open-source security layer for AI agents. Deny-by-default enforcement, human approvals, and a cryptographically signed audit trail — so your agent runs only what it's granted and provably can't approve its own work. Website · Live Demo · mc scan · Docs Your agents keep running in their existing framework (LangChain, Claude SDK, CrewAI). MakerChecker sits in front of every tool call as a checkpoint and behind it as a signed ledger: an agent acts only through a role , runs only the skills it was granted , cannot exceed its limits, and cannot approve its own work. --- 🚀 Quick Start 1 — Scan your code Find what your agent can already do on its own, classified by risk. No install, nothing leaves your machine: It flags every consequential action — deleting data, moving money, running shell commands, exfiltrating secrets — names each against the real incident it resembles, and can write the governance code for you with --fix . → packages/scan 2 — Guarantee its behavior Import the controls and wrap any tool. The agent can now only run what its role was granted — a call it isn't allowed is denied before it executes: High-risk skills go to a separate role, so an agent can never approve its own work — and every decision, allowed or denied, commits to a signed audit log. → packages/embedded 3 — Working with auditors? Step 2 already writes a signed log. When auditors need a durable, queryable, tamper-evident record — plus a human-approval inbox and a review console —","default_branch":null,"files":null,"tree":[],"storefront":"/r/makerchecker","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/makerchecker/MakerChecker/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}