Governance, audit, and discipline frameworks for AI coding agents — deterministic workflows, context budgets, tool gating, usage tracking.
Agent Governance tools are AI-powered software designed to help developers and teams tackle agent governance-related tasks more efficiently. These tools are typically published as open-source projects on GitHub and can be integrated into existing workflows via MCP (Model Context Protocol), Claude Skills, or standalone agent frameworks. On Agent Skills Hub, we index 30 quality-scored agent governance tools across languages including Shell, Python, Rust.
In 2026, the AI agent ecosystem is maturing rapidly. Agent Governance tools can significantly boost development efficiency by automating repetitive tasks, reducing human error, and providing intelligent suggestions. The top 3 tools — skills, keep-codex-fast, agentseal — have earned an average of 6,523 GitHub stars, reflecting strong community validation. 18 of the listed tools come with clear open-source licenses, ensuring freedom to use and modify.
When choosing a agent governance tool, consider these factors: 1) Community activity — GitHub stars and recent commit frequency indicate reliability; 2) Integration method — check if it supports MCP, Claude, or your preferred agent framework; 3) Language compatibility — the most common language in this list is Shell; 4) Quality score — Agent Skills Hub's composite score evaluates code quality, documentation completeness, and maintenance activity. Our recommendation: start with skills — it ranks highest in both star count and quality score.
Skills for Real Engineers. Straight from my .claude directory.
A backup-first Codex skill for keeping local Codex state fast, clean, and recoverable.
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection resistance, and audit live MCP servers for tool poisoning.
Curated, production-grade skills for AI coding agents. Battle-tested workflows for developers who use AI seriously.
Intercept and inspect Coding Agent API traffic from Claude Code, Codex CLI, Gemini CLI, Cursor CLI, OpenCode, Kimi/Kimi Code, Pi, and Hermes in a local trace viewer.
AI agents are getting tool access — shell, file system, databases, APIs, secrets. But **nobody is governing what they actually do with it**. Frameworks like LangChain, CrewAI, AutoGen, and Claude Code give agents the power to execute. Agent Armor gives you the power to control, audit, and approve every single action before it happens.
Constitution-first AI orchestration: one Charter (YAML) defines mission, budget & rules. CEO plans → CFO approves → Ledger tracks every cent & token → Auditor scores. 16 workers, Stripe, MCP. Think. Audit. Execute.
Pi coding-agent extension for pruning tool-call trees
Claude Code usage governor: compact professional output, context slimming, tool-output filtering, telemetry, and drift guardrails.
```bash
bash install.sh --force
```
🛩️ Git-native workflow control for coding agents: approved plans, verification, and reviewable evidence for Claude Code, Codex, Cursor, and Aider.
TDD enforcement and guardrails for Claude Code, Codex, and GitHub Copilot CLI
One command. 29 battle-tested security checks built into every AI coding assistant you already use without leaving your IDE.
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
MCP server for AI agent for cybersecurity: automate assessment of documents, questionnaires & reports. Multi-format parsing, RAG knowledge base,Risks, compliance gaps, remediations.
🎱 AI Agent Governance Framework — Constrain how AI Agents behave in your project. pip install pattern8
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, Australia's ISM, EU NIS2, CCPA/CPRA, and others. Benchmark 97% (with skills) vs 81% (without skills).
EU AI Act compliance proxy for AI systems. Drop-in HTTP proxy that monitors every AI interaction for regulatory risks, logs to a tamper-proof audit trail, and generates legal-grade PDF reports. 143 rules across 8 Annex III domains. Self-hosted, open-core
AgentGuard:An Attribute-Based Access Control Framework for Tool-Use LLM-Based Agent
Govrix Scout — AI Agent Governance Diagnostic Tool (OSS)
YAO = Yielding AI Outcomes. A rigorous engineering, evaluation, governance, and portability system for reusable agent skills.
The Enterprise Architecture Governance Harness — strategy, architecture, delivery, and assurance using AI coding assistants
Prompt-as-Code for Enterprise AI. Standardize, audit, and deploy instructions across any AI coding assistant.
The action firewall for AI agents. Enforce policy and human approval before risky tool calls, shell commands, workflows, and production changes, with auditable evidence.
Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
Python and TypeScript SDKs for verifiable evidence of AI agent actions. Signed receipts, policy enforcement, audit trails. Works with LangChain, CrewAI, MCP.
🛡️The governance runtime for AI agents. Intercept actions, enforce guard policies, require approvals, and produce audit-ready decision trails.
Open-source Tax Guides for AI agents, reviewed by named CPAs/CAs/EAs. 1,000+ Guides across 190+ jurisdictions. MCP server included. Works with Claude, ChatGPT, Cursor.
Agyn is an open-source Kubernetes-native runtime that moves AI agents like Claude Code and Codex from laptops to company infrastructure with the controls enterprises need.
Claude Code skill plugins for financial services — 81 skills across 7 domain plugins covering investment management, compliance, advisory practice, trading, and operations.
| Tool | Stars | Language | License | Score |
|---|---|---|---|---|
| skills | ★ 173.9k | Shell | MIT | 82 |
| keep-codex-fast | ★ 805 | Python | MIT | 61 |
| agentseal | ★ 285 | Python | — | 56 |
| armory | ★ 272 | Python | MIT | 64 |
| claude-tap | ★ 2.6k | Python | MIT | 72 |
| IAGA-Sentinel | ★ 120 | Rust | — | 53 |
| Sovereign-OS | ★ 100 | Python | — | 67 |
| pi-context-prune | ★ 199 | TypeScript | — | 66 |
| governor | ★ 118 | Python | MIT | 72 |
| agentplane | ★ 72 | TypeScript | MIT | 62 |
| probity | ★ 81 | TypeScript | MIT | 61 |
| skill-file-security | ★ 66 | JavaScript | — | 70 |
| agent-governance-toolkit | ★ 4.9k | Python | MIT | 81 |
| DocSentinel | ★ 97 | Python | MIT | 61 |
| pattern8 | ★ 99 | Python | MIT | 52 |
| ciso-assistant-community | ★ 4.3k | Python | — | 71 |
| Claude-Skills-Governance-Risk-and-Compliance | ★ 762 | HTML | MIT | 66 |
| aulite | ★ 112 | TypeScript | — | 58 |
| AgentGuard | ★ 71 | Python | GPL-3.0 | 57 |
| govrix-scout | ★ 74 | Rust | — | 45 |
| yao-meta-skill | ★ 2.1k | Python | MIT | 79 |
| arc-kit | ★ 2.1k | JavaScript | — | 68 |
| promptscript | ★ 475 | TypeScript | MIT | 66 |
| cordum | ★ 494 | Go | — | 63 |
| claude-grc-engineering | ★ 350 | JavaScript | — | 69 |
| asqav-sdk | ★ 253 | Python | — | 69 |
| DashClaw | ★ 284 | TypeScript | MIT | 62 |
| openaccountants | ★ 259 | Python | AGPL-3.0 | 65 |
| platform | ★ 203 | TypeScript | AGPL-3.0 | 72 |
| finance_skills | ★ 152 | Python | MIT | 69 |
The top agent governance tools in 2026 are skills, keep-codex-fast, agentseal. Agent Skills Hub ranks 30 options by GitHub stars, quality score (6 dimensions including completeness, examples, and agent readiness), and recent activity. The list is rebuilt every 8 hours from live GitHub data.
skills (173.9k stars) is the most adopted choice for general agent governance workflows, written in Shell. keep-codex-fast (805 stars) is a strong alternative and uses Python instead. Pick by your existing stack: match the language and runtime your team already uses to minimize integration cost. If unsure, start with skills — it has the deepest community and the most examples online.
Avoid pre-built agent governance tools when (1) your use case requires deep customization that the tool's plugin system doesn't support, (2) you have strict compliance requirements that ban third-party dependencies, (3) the tool's maintenance is inactive (last commit >6 months ago), or (4) your data volume is small enough that a 50-line custom script is cheaper than learning the tool. For most production workflows above 100 requests/day, the time savings from a maintained tool outweigh the customization loss.
Agent Governance focuses specifically on governance, audit, and discipline frameworks for ai coding agents — deterministic workflows, context budgets, tool gating, usage tracking. AI Code Editors is a related but distinct category — see https://agentskillshub.top/best/ai-code-editor/ for those tools. The two often appear in the same agent pipeline but solve different problems: choose agent governance when your primary goal is the specific task, and ai code editors when the workflow is broader.
For most teams, yes. skills has 173.9k stars worth of community testing, handles edge cases you haven't thought of, and ships with documentation. Build your own only when (1) your requirements are deeply non-standard, (2) you have a security/compliance reason to avoid OSS dependencies, or (3) the maintenance burden is small enough (<200 lines of code) that you'll save time long-term. The break-even point is usually around 2-3 weeks of dev time saved.
Most agent governance tools listed are open source under permissive licenses (MIT, Apache 2.0). A handful offer paid managed/cloud versions on top of free self-hosted core. Always check the LICENSE file on each tool's GitHub repository before commercial use — some use AGPL or non-commercial restrictions that may not fit your deployment model.