Skip to content
#

capability-security

Here are 16 public repositories matching this topic...

KAIROS-ARK is a high-performance, Rust-based Agent Runtime Kernel built for industrial-grade reliability. It delivers sub-100µs dispatch latency, event-sourced deterministic replay, and kernel-enforced capability sandboxing, bridging Python prototypes and production AI systems.

  • Updated Dec 21, 2025
  • Rust
command-scope-contract

Bounded shell and CLI execution for AI agents: structured contracts, policy-gated execution, hardened Linux runtime enforcement, and signed receipts.

  • Updated Mar 30, 2026
  • Python
kingpin_demo

Toy governance CLI demo: deny-by-default “danger actions” gated by signed, expiring capability leases (global revoke-all + nonce revoke) plus guarded memory quarantine. Simulation-only: no real network/shell/files. Includes tripwire + tests to prevent misuse.

  • Updated Feb 17, 2026
  • Python
Oreulius-Kernel

A WASM‑first, capability‑native unikernel designed to run small, isolated WASI workloads on edge/cloud hosts, providing deterministic temporal snapshots, capability‑based authority transfer, and in‑kernel verification to enable secure, auditable migration and replay. It targets security and audit-sensitive deployments and systems‑research

  • Updated Apr 5, 2026
  • Rust

Improve this page

Add a description, image, and links to the capability-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the capability-security topic, visit your repo's landing page and select "manage topics."

Learn more