Skip to content

Entry

NeMo Guardrails

Appears in 6 awesome lists

NVIDIA's programmable guardrails toolkit: define input, dialog, retrieval, execution, and output rails that intercept the agent loop at five distinct layers using the Colang DSL. The execution rail layer specifically governs what tools the LLM can invoke and what their inputs/outputs may contain —…

Open github.comnvidia-nemo/guardrails

Found in these lists

Awesome AI Security Tools

Section: Scanners, Evals & Guardrails · 🟢 — Programmable guardrails (input/output/dialog/retrieval rails) for LLM apps. (NVIDIA) · updated 2026-08-17)

FreshScore 85

Awesome Harness Engineering

Section: Security, Sandbox & Permissions · NVIDIA's programmable guardrails toolkit: define input, dialog, retrieval, execution, and output rails that intercept the agent loop at five distinct layers using the Colang DSL. The execution rail layer specifically governs what tools the LLM can invoke and what their inputs/outputs may contain —…

FreshScore 88

Awesome local LLM

Section: Security and Sandboxing · an open-source toolkit from NVIDIA for easily adding programmable guardrails to LLM-based conversational systems

FreshScore 87

Awesome Open Source AI

Section: 10. AI Safety, Alignment & Interpretability · Programmable guardrails toolkit for LLM-based conversational systems. Uses Colang DSL to define safety rules, dialog flows, and content boundaries. Integrates with LangChain, LangGraph, and LlamaIndex for production deployments. Apache 2.0 licensed.

FreshScore 89

Awesome Production Machine Learning

Section: Privacy and Safety · NeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.

FreshScore 92

awesome-python

Section: LLM and Inference · NeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.

FreshScore 81

promptfoo

Test your prompts, models, RAGs. Evaluate and compare LLM outputs, catch regressions, and improve prompt quality. LLM evals for OpenAI/Azure GPT, Anthropic Claude, VertexAI Gemini, Ollama, Local & private models like Mistral/Mixtral/Llama with CI/CD

In 11 listsDetails

E2B

Firecracker microVM sandboxes purpose-built for agent tool loops: ~150ms cold start, Python/JS SDKs, open source. The clearest reference implementation of "code execution as a harness primitive" rather than a CI system bolted on.

In 7 listsDetails

Guardrails AI

Input/output validation framework for building reliable AI applications. Detects and mitigates risks through composable validators for PII, toxicity, prompt injection, and structured output validation. Features Guardrails Hub with 50+ pre-built validators. Apache 2.0 licensed.

In 6 listsDetails

TextAttack

Python framework for adversarial attacks, data augmentation, and model training in NLP. Augment datasets to increase model robustness and generate adversarial examples. MIT licensed.

In 6 listsDetails

Agent Governance Toolkit

🟢 — Multi-language toolkit for policy-enforced agent tool calls and audit records, with optional identity, MCP-gateway, sandboxing, reliability, and compliance components. (Microsoft) — note: official public preview; APIs and deployment patterns may change before general availability. · updated…;…

In 5 listsDetails

garak

The LLM vulnerability scanner. Probes models for hallucinations, data leakage, prompt injection, misinformation, toxicity, and jailbreaks. Extensive plugin-based architecture with 100+ vulnerability probes. Apache 2.0 licensed.

In 4 listsDetails

CubeSandbox

Tencent Cloud's production-validated microVM sandbox for AI agents: sub-60ms cold start via snapshot cloning, <5MB per-instance overhead, and true kernel-level isolation with eBPF-enforced network policies. E2B-compatible drop-in replacement that demonstrates how hyperscale cloud infrastructure…

In 4 listsDetails

OpenShell

Open-source policy-driven sandbox runtime for autonomous AI agents, announced at GTC 2026. Enforces security constraints at the kernel level via Landlock LSM (filesystem), seccomp BPF (syscalls), and an OPA/Rego-evaluated HTTP CONNECT proxy (network) — constraints are enforced on the environment…

In 4 listsDetails