Ross ROSS = Recommend OSS · open-source software intelligence for agents

akto-api-security/akto

Akto is the fastest growing AI Security platform for your teams to secure AI agents, MCPs, LLMs, Agent skills, Gen AI apps in your organization. observed · 2026-08-28

github.com/akto-api-security/akto · homepage · Java · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 99
  • Release rhythm 87
  • Longevity 93
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0.0
  • age_days: 1310
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 1543

Full methodology

Adoption not part of the score

1505 stars · 292 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Akto is an open-source API and AI security platform that discovers and inventories APIs, AI agents, MCP servers, and LLM usage, then continuously tests them for vulnerabilities and enforces real-time guardrails. It covers OWASP API/LLM/Agentic Top 10 risks through automated red teaming, runtime threat protection, and posture management, deployable self-hosted or in the cloud.

Use cases

  • discover and inventory all APIs and AI agents across my infrastructure
  • test my APIs for vulnerabilities like BOLA, SSRF, and XSS
  • run automated red teaming against my LLM and AI agent applications
  • enforce guardrails to stop prompt injection and PII leakage in AI tools
  • find shadow AI usage on employee endpoints
  • secure MCP servers and agentic AI workflows
  • monitor API traffic for runtime threats
  • achieve compliance with OWASP LLM Top 10 and EU AI Act

When to choose

  • you need continuous API security testing and inventory across microservices
  • your organization deploys LLM apps, AI agents, or MCP servers and needs visibility and guardrails
  • you want an open-source, self-hosted alternative to commercial API security products
  • you need automated red teaming mapped to OWASP API/LLM/Agentic Top 10

When to avoid

  • you only need a simple web application firewall without API discovery or testing
  • you need endpoint antivirus or traditional network security rather than API/AI-layer protection
  • you want a lightweight library to embed in code rather than a full platform deployment

Facets

application · maturity active

security vulnerability-scanning penetration-testing monitoring api-gateway llm-inference mcp agent-framework testing security artificial-intelligence large-language-models apis developer-tools self-hosted cloud windows api-security ai-security red-teaming guardrails owasp-llm-top-10 owasp-agentic-top-10 prompt-injection dast api-inventory traffic-mirroring agentic-ai shadow-ai-discovery ai-agents devops docker kubernetes web-server linux macos

6 sources

Member repositories

RepositoryRoleHealth v2
akto-api-security/aktomain94

For agents

markdown · JSON · MCP: product_card(name="akto-api-security/akto")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem