Skip to content
#

capability-based-security

Here are 50 public repositories matching this topic...

open-thymos

Governed AI agent runtime with a local-first desktop app + CLI. Chat with any model (Claude, OpenAI, Groq, Ollama, LM Studio); every action passes Intent → Proposal → Commit through signed capability writs, risk-gated approvals, and a replayable hash-chained ledger. Watch it think in the Mind graph. Cognition proposes; the runtime governs.

  • Updated Jun 12, 2026
  • Rust

Three packages: @kernel.chat/agent-os (POSIX for AI agents — capabilities, namespaces, quotas, taint, audit, vault, outcomes), @kernel.chat/kbot (terminal AI agent, MCP-native, BYOK), @kernel.chat/kbot-finance (audit-grade AI for regulated industries). Provenance-engineering substrate.

  • Updated Jun 11, 2026
  • TypeScript

InferNode is a security-focused 64-bit Inferno® OS (ARM64/AMD64) for embedded systems, servers, and AI agents. GPL-free, headless-capable, with 280+ utilities and 9P filesystem protocol. Providing a namespace-based alternative to MCP servers. Namespace-bounded security has been formally verified.

  • Updated Jun 9, 2026
  • Limbo

A data-driven, cryptographically signed, registry-backed AI operating system, with capability-scoped execution and graph-executable workflows — living inside your projects, running through a recursive MCP that goes as deep as you dare.

  • Updated Jun 11, 2026
  • Rust

Improve this page

Add a description, image, and links to the capability-based-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the capability-based-security topic, visit your repo's landing page and select "manage topics."

Learn more