OpenAPPA – deterministic AI guardrails that don't break agents
An information-flow policy engine for LLM agents.
OpenAPPA – deterministic AI guardrails that don't break agents launched on September 28, 2026 with 25 votes, #696 of 8,042 launches that month and more than 90% of that year's launches.
In plain words
OpenAPPA is an information-flow policy engine designed to protect LLM agents from data exfiltration caused by prompt injection or model hallucination. It works by monitoring data flow across tool calls rather than relying on a separate classifier model, which avoids the security vulnerabilities of judge-based approaches. The system is built for teams deploying autonomous agents who need security guardrails without sacrificing agent functionality.
written from the facts on this page · September 2026
From the sources
OpenAPPA is a frontier deterministic AI guardrail that is 100% resistant to data exfiltration caused by prompt injection or model hallucination, and the first of its kind that doesn't break agents. The industry's answer to approval fatigue is a second model that judges each tool call: Claude Code's auto mode, Codex's auto-review, and other auto-modes . By design, they cannot track data flow across tool calls. Because classifiers are prompt-injectable themselves, harnesses hide tool outputs from them, so the judge never sees the data at all. Because of their probabilistic design, even the best top out at 99.3% : at millions of calls, 0.7% is a lot of breaches. Blacklisting commands against…from openappa.com
Does a similar job
all alternatives →

Open AgentsApr 2026 · open-agents.dev · ▲161OpenAgents - The collaboration OS for AI agents. Contribute to openagents-org/openagents development by creating an account on GitHub.
We post-trained a model that pen tests instead of refusingJun 2026 · argusred.com · ▲93Anthropic and OpenAI's publicly available models are explicitly guard-railed so that they refuse offensive tasks. And their cyber-focussed models are gated for enterprises. This leaves SMEs and mid market open to major vulnerabilities. AI can be used as both an adversarial and defensive tool in the world of cyber. A worst case outcome is if only the adversaries have access. Meanwhile, most existing AI cyber tools are just wrappers. The problem is that they still have all the guardrails on from the foundation model where they will inherit its refusals. For this project we've post-trained a…

- OS
More ai this month
the category →
E-ink bird frame for Raspberry Pi - real-time bird detection by audio, fully local AI, rendered as real, hand-cut 1800s bird illustrations. - arnegiacomo/fugleramme
AI · 17d ago · github.com





Launched alongside, September 2026
the whole month →
E-ink bird frame for Raspberry Pi - real-time bird detection by audio, fully local AI, rendered as real, hand-cut 1800s bird illustrations. - arnegiacomo/fugleramme
AI · 17d ago · github.com
- WI
Special relativity simulator in which light crawls along at a human speed, so Lorentz contraction, aberration and Doppler shift happen at walking pace.
Life & fun · 23d ago · rivendell.dmitrybrant.com


Start coding agents, control sessions, review PRs. Anywhere.
Dev tools · 22d ago · kilo.ai

