Governance, audit, and discipline frameworks for AI coding agents — deterministic workflows, context budgets, tool gating, usage tracking.
Agent Governance tools are AI-powered software designed to help developers and teams tackle agent governance-related tasks more efficiently. These tools are typically published as open-source projects on GitHub and can be integrated into existing workflows via MCP (Model Context Protocol), Claude Skills, or standalone agent frameworks. On Agent Skills Hub, we index 30 quality-scored agent governance tools across languages including Shell, Python, Rust.
In 2026, the AI agent ecosystem is maturing rapidly. Agent Governance tools can significantly boost development efficiency by automating repetitive tasks, reducing human error, and providing intelligent suggestions. The top 3 tools — skills, keep-codex-fast, agentseal — have earned an average of 9,890 GitHub stars, reflecting strong community validation. 19 of the listed tools come with clear open-source licenses, ensuring freedom to use and modify.
When choosing a agent governance tool, consider these factors: 1) Community activity — GitHub stars and recent commit frequency indicate reliability; 2) Integration method — check if it supports MCP, Claude, or your preferred agent framework; 3) Language compatibility — the most common language in this list is Shell; 4) Quality score — Agent Skills Hub's composite score evaluates code quality, documentation completeness, and maintenance activity. Our recommendation: start with skills — it ranks highest in both star count and quality score.
Skills for Real Engineers. Straight from my .claude directory.
A backup-first Codex skill for keeping local Codex state fast, clean, and recoverable.
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection resistance, and audit live MCP servers for tool poisoning.
Curated, production-grade skills for AI coding agents. Battle-tested workflows for developers who use AI seriously.
Intercept and inspect Coding Agent API traffic from Claude Code, Codex CLI, Gemini CLI, Cursor CLI, OpenCode, Kimi/Kimi Code, Pi, and Hermes in a local trace viewer.
AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens.
Constitution-first AI orchestration: one Charter (YAML) defines mission, budget & rules. CEO plans → CFO approves → Ledger tracks every cent & token → Auditor scores. 16 workers, Stripe, MCP. Think. Audit. Execute.
Pi coding-agent extension for pruning tool-call trees
Claude Code usage governor: compact professional output, context slimming, tool-output filtering, telemetry, and drift guardrails.
```bash
bash install.sh --force
```
🛩️ Git-native workflow control for coding agents: approved plans, verification, and reviewable evidence for Claude Code, Codex, Cursor, and Aider.
TDD enforcement and guardrails for Claude Code, Codex, and GitHub Copilot CLI
One command. 29 battle-tested security checks built into every AI coding assistant you already use without leaving your IDE.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
🛡️ A curated list of tools, frameworks, standards, and resources for AI agent governance, safety, and compliance
MCP server for AI agent for cybersecurity: automate assessment of documents, questionnaires & reports. Multi-format parsing, RAG knowledge base,Risks, compliance gaps, remediations.
🎱 AI Agent Governance Framework — Constrain how AI Agents behave in your project. pip install pattern8
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 200+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, CCPA/CPRA, and others. Benchmark 89% (with skills) vs 57% (without skills). Updated Monthly.
EU AI Act compliance proxy for AI systems. Drop-in HTTP proxy that monitors every AI interaction for regulatory risks, logs to a tamper-proof audit trail, and generates legal-grade PDF reports. 143 rules across 8 Annex III domains. Self-hosted, open-core
AgentGuard:An Attribute-Based Access Control Framework for Tool-Use LLM-Based Agent
Govrix Scout — AI Agent Governance Diagnostic Tool (OSS)
✅ AI governance skill for Claude Code | AI 治理框架 | AI ガバナンスフレームワーク — Safety gates, evidence rules, anti-slack
YAO = Yielding AI Outcomes. A rigorous engineering, evaluation, governance, and portability system for reusable agent skills.
Build tested agent skills and govern their lifecycle through a user-defined marketplace: evidence, discovery, updates, rollback, quarantine, and 17-platform distribution.
Build tested agent skills and govern their lifecycle through a user-defined marketplace: evidence, discovery, updates, rollback, quarantine, and 17-platform distribution.
The Enterprise Architecture Governance Harness — strategy, architecture, delivery, and assurance using AI coding assistants
Decision audit trail + persistent memory for AI trading agents. Outcome-weighted recall, tamper-evident SHA-256 chain with RFC 3161 anchoring, 20 MCP tools.
Python and TypeScript SDKs for verifiable evidence of AI agent actions. Signed receipts, policy enforcement, audit trails. Works with LangChain, CrewAI, MCP.
聂·基层运行逻辑 · Agent Skill:基于聂辉华《基层中国的运行逻辑》的方法论工具箱(不含原书全文)
The action firewall for AI agents. Enforce policy and human approval before risky tool calls, shell commands, workflows, and production changes, with auditable evidence.
| Tool | Stars | Language | License | Score |
|---|---|---|---|---|
| skills | ★ 265.8k | Shell | MIT | 82 |
| keep-codex-fast | ★ 1.5k | Python | MIT | 61 |
| agentseal | ★ 375 | Python | — | 56 |
| armory | ★ 318 | Python | MIT | 64 |
| claude-tap | ★ 3.2k | Python | MIT | 72 |
| IAGA-Sentinel | ★ 120 | Rust | — | 53 |
| Sovereign-OS | ★ 92 | Python | — | 66 |
| pi-context-prune | ★ 237 | TypeScript | — | 67 |
| governor | ★ 133 | Python | MIT | 77 |
| agentplane | ★ 77 | TypeScript | MIT | 62 |
| probity | ★ 207 | TypeScript | MIT | 63 |
| skill-file-security | ★ 71 | JavaScript | — | 70 |
| agent-governance-toolkit | ★ 6.3k | Python | MIT | 82 |
| awesome-ai-governance | ★ 50 | Shell | CC0-1.0 | 62 |
| DocSentinel | ★ 87 | Python | MIT | 60 |
| pattern8 | ★ 51 | Python | MIT | 52 |
| ciso-assistant-community | ★ 4.4k | Python | — | 72 |
| Claude-Skills-Governance-Risk-and-Compliance | ★ 894 | HTML | MIT | 66 |
| aulite | ★ 130 | TypeScript | — | 58 |
| AgentGuard | ★ 115 | Python | GPL-3.0 | 57 |
| govrix-scout | ★ 72 | Rust | — | 45 |
| yes.md | ★ 50 | Shell | MIT | 57 |
| yao-meta-skill | ★ 2.4k | Python | MIT | 77 |
| agent-skill-creator | ★ 2.4k | Python | MIT | 70 |
| agent-skills-platform | ★ 2.4k | Python | MIT | 69 |
| arc-kit | ★ 2.2k | JavaScript | — | 69 |
| tradememory-protocol | ★ 1.4k | Python | MIT | 72 |
| asqav-sdk | ★ 550 | Python | — | 69 |
| nie-grassroots-logic | ★ 551 | HTML | MIT | 61 |
| cordum | ★ 507 | Go | — | 63 |
The top agent governance tools in 2026 are skills, keep-codex-fast, agentseal. Agent Skills Hub ranks 30 options by GitHub stars, quality score (6 dimensions including completeness, examples, and agent readiness), and recent activity. The list is rebuilt every 8 hours from live GitHub data.
skills (265.8k stars) is the most adopted choice for general agent governance workflows, written in Shell. keep-codex-fast (1.5k stars) is a strong alternative and uses Python instead. Pick by your existing stack: match the language and runtime your team already uses to minimize integration cost. If unsure, start with skills — it has the deepest community and the most examples online.
Avoid pre-built agent governance tools when (1) your use case requires deep customization that the tool's plugin system doesn't support, (2) you have strict compliance requirements that ban third-party dependencies, (3) the tool's maintenance is inactive (last commit >6 months ago), or (4) your data volume is small enough that a 50-line custom script is cheaper than learning the tool. For most production workflows above 100 requests/day, the time savings from a maintained tool outweigh the customization loss.
Agent Governance focuses specifically on governance, audit, and discipline frameworks for ai coding agents — deterministic workflows, context budgets, tool gating, usage tracking. AI Code Editors is a related but distinct category — see https://agentskillshub.top/best/ai-code-editor/ for those tools. The two often appear in the same agent pipeline but solve different problems: choose agent governance when your primary goal is the specific task, and ai code editors when the workflow is broader.
For most teams, yes. skills has 265.8k stars worth of community testing, handles edge cases you haven't thought of, and ships with documentation. Build your own only when (1) your requirements are deeply non-standard, (2) you have a security/compliance reason to avoid OSS dependencies, or (3) the maintenance burden is small enough (<200 lines of code) that you'll save time long-term. The break-even point is usually around 2-3 weeks of dev time saved.
Most agent governance tools listed are open source under permissive licenses (MIT, Apache 2.0). A handful offer paid managed/cloud versions on top of free self-hosted core. Always check the LICENSE file on each tool's GitHub repository before commercial use — some use AGPL or non-commercial restrictions that may not fit your deployment model.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: