ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.
-
Updated
Sep 1, 2026 - Rust
ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.
Run AI harnesses like Claude Code, Codex, Copilot, Antigravity, and Omnigent in disposable workspace forks. Review, merge, or roll back changes with policy enforcement and provenance.
Runtime enforcement boundary for AI agents: a local sidecar that gates every outbound call against Cedar policies you own. Deterministic, call-level, no model on the hot path
eBPF Security Monitoring and Sandboxing Agent Based on Aya
Agent Reference Stack for Kubernetes (kars) - an open source stack from Microsoft for running AI agents safely on Kubernetes. Multi-runtime, Foundry-aware, hardened per-agent sandboxes, governed egress, end-to-end encrypted inter-agent mesh.
Governed AI agent runtime with a local-first desktop app + CLI. Chat with any model (Claude, OpenAI, Groq, Ollama, LM Studio); every action passes Intent → Proposal → Commit through signed capability writs, risk-gated approvals, and a replayable hash-chained ledger. Watch it think in the Mind graph. Cognition proposes; the runtime governs.
eBPF-based per-tool syscall attribution and enforcement for LLM agents
Runtime security monitor for AI coding agents
Core Rust library for Lens sandbox policy enforcement, networking, DNS, proxying, and boundary credential exchange.
OS-level runtime security for AI agents. Tamper-proof monitoring, behavioral detection, and audit trails.
Monitor AI coding agents in real-time to block unauthorized file access, network connections, and dangerous commands while enforcing system resource limits.
A modular Next-Generation Antivirus (NGAV) and Endpoint Detection & Response (EDR) for Linux, leveraging eBPF (LSM) and Rust for memory-safe userland.
RAXIS (Runtime Attestation eXchange for Intelligent Systems) — Structural confinement kernel for autonomous AI agents. 12 non-negotiable invariants enforce that intelligence can't do anything authority didn't structurally permit. Isolated microVMs, cryptographic audit chains, credential proxies, fail-closed intent admission.
Clampd - Runtime Security for AI Agents. Dev infrastructure and orchestration.
Secure-execution domain repository providing modular runtime-security components for sandboxing, capability enforcement, cryptographic isolation, audit logging, and policy-driven execution control — designed for building hardened application and infrastructure runtimes.
A dual-module eBPF security research framework demonstrating offensive rootkit techniques (Shadow) and defensive runtime auditing (Aegis) for Linux kernel exploration.
Behavioral security layer for NVIDIA OpenShell — patent-pending DFS-based agent behavioral analysis
Runtime Security & Alignment Layer for Autonomous AI Agents. eBPF-based sandbox with DEFCON threat levels and Cgroup isolation.
Apolysis is an environment-owned runtime accountability layer for opaque or semi-trusted AI Agent workloads.
To associate your repository with the runtime-security topic, visit your repo's landing page and select "manage topics."