Vibeleaderboard
Index / tool
Visit github.com
Category
Cybersecurity
Rank
No. 1150Tools index
Pricing
Open Source
Platform
cli
Type
TOOL
GitHub
8 stars
Latest release
v0.10.1
Date

About

Stroq is a local, deterministic firewall that hooks into AI coding agents (Claude Code, Cursor, Codex, Copilot CLI, Windsurf, OpenClaw, MCP clients) to scan content the agent reads for injected instructions, taint the session, and block or ask before risky follow-up actions like shell execution, secret exfiltration, or external git pushes. It ships a built-in replay suite that tests the default policy against 13 real-world agent-hijacking incidents, all fully offline with no cloud dependency.

What it can do

  • Scan content read by AI coding agents for injected instructions

    Content read by AI agent (files, web pages, tool output)Detection of prompt injection attempts

  • Taint session state when malicious content is detected

    Scan resultsTainted session flag

  • Block or prompt for confirmation before risky follow-up actions (shell execution, secret exfiltration, external git pushes)

    Agent action requestAllow/block/ask decision

  • Run a built-in replay suite testing default policy against 13 documented real-world agent-hijacking incidents

    Recorded attack scenariosPass/fail results per incident

Why it made the leaderboard

Blocks the pattern where an agent reads malicious instructions from a file or page and then acts on them, by tracking taint across the session and gating risky follow-up commands.

Tags

ai-securityprompt-injectionagent-securityfirewallclimcpclaude-codedeveloper-tools

Tech Stack

Node.js

Media

Stroq

Comments (0)

No comments yet

Editorially curated, with community endorsements as a secondary signal. Corrections welcome.