Skip to content
Kontext Security

Agent security. Enforced before execution.

Kontext applies identity-aware policy to AI agent actions.
Sandy contains AI coding agents with native macOS and Linux sandboxing.

Get started with Kontext · Documentation · Website

GitHub Stars Follow on X

Control what AI agents can do

AI agents can chain individually permitted operations into outcomes nobody intended.

Kontext gives agents a runtime identity, evaluates supported tool calls against policy, and blocks disallowed actions before they reach protected systems. Every decision produces evidence showing what the agent attempted, which policy applied, and why the action was allowed or denied.

brew install kontext-security/tap/kontext

View the Kontext repository →

Add process containment with Sandy

Sandy confines AI coding agents to explicitly permitted files, network destinations, and processes using native operating-system sandboxing on macOS and Linux.

brew install kontext-security/tap/sandy

View the Sandy repository →

Two complementary security layers

Layer Question it answers Project
Runtime authorization Should this supported agent action proceed under policy? Kontext
Process containment What can this agent process access on the machine? Sandy for macOS and Linux

Use them independently or together for defense in depth.

Open-source projects

Repository Description
kontext Identity-aware runtime policy enforcement for AI agents
sandy Native process containment for AI coding agents on macOS and Linux
agent-skills Skills and integrations for using Kontext with AI agents

Join the community

Pinned Loading

  1. kontext kontext Public

    Secure agents in seconds with permissions enforced at runtime.

    Go 221 7

Repositories

Showing 10 of 14 repositories
  • kontext Public

    Secure agents in seconds with permissions enforced at runtime.

    kontext-security/kontext's past year of commit activity
    Go 221 MIT 7 1 22 Updated Sep 18, 2026
  • homebrew-tap Public
    kontext-security/homebrew-tap's past year of commit activity
    Ruby 0 0 0 0 Updated Sep 18, 2026
  • agent-skills Public
    kontext-security/agent-skills's past year of commit activity
    Python 0 0 0 1 Updated Sep 14, 2026
  • sandy Public

    Secure agents in seconds by running them in a sandbox.

    kontext-security/sandy's past year of commit activity
    Rust 5 MIT 0 3 5 Updated Sep 1, 2026
  • claude-code-env-exfil-test Public

    Reproduce a Claude Code repository-instruction test with Kestrel classification and Cedar enforcement.

    kontext-security/claude-code-env-exfil-test's past year of commit activity
    Python 0 MIT 0 0 0 Updated Aug 30, 2026
  • .github Public

    Kontext organization profile and community health files

    kontext-security/.github's past year of commit activity
    0 0 0 0 Updated Aug 30, 2026
  • shellrisk-bench Public

    A reproducible benchmark for context-free shell-command risk classification

    kontext-security/shellrisk-bench's past year of commit activity
    Python 3 Apache-2.0 0 0 0 Updated Aug 20, 2026
  • agent-browser Public

    One connection for all your MCP servers.

    kontext-security/agent-browser's past year of commit activity
    Go 63 MIT 6 0 1 Updated May 20, 2026
  • attestable-mcp-server Public

    Verify that any MCP server is running the intended and untampered code via hardware attestation.

    kontext-security/attestable-mcp-server's past year of commit activity
    Python 21 7 0 4 Updated May 20, 2026
  • browser-use-mcp-server Public

    Browse the web, directly from Cursor etc.

    kontext-security/browser-use-mcp-server's past year of commit activity
    Python 843 MIT 115 18 5 Updated May 20, 2026

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…