AILANTA
All research
GitHub · npm · Discovery evidence

Agent security is becoming a runtime stack

A seven-month GitHub, package, and incident-evidence cohort measures identity, sandboxing, authorization, audit, and recovery around autonomous actions.

2026-08-06255 items8 source types7 validation posts
Main finding

Supported by the targeted cohort

255 subject-filtered implementations show a real runtime-security category. Sandboxing appears in 37.3% of the cohort, authorization and policy in 13.3%, and runtime identity in 8.6%. Recovery and containment remain thinner at 2.7%, so prevention is forming faster than safe failure recovery.

01

Market snapshot

Comparable measurements from independent market surfaces.

255

Implementations and packages

Deduplicated and subject-filtered primary cohort.

7

Median repository stars

Calculated across repositories with at least one star.

30

Registry packages

Real npm and PyPI package records, not synthetic entries.

101,139

Latest-month npm downloads

Usage surface only; downloads are not equivalent to customers.

02

Search-match dynamics

Bars show monthly GitHub Search API matches across three runtime-security queries; loaded counts are deduplicated repositories retained for detailed analysis.

Jan 2615526 loaded
Feb 2626448 loaded
Mar 2635045 loaded
Apr 2623429 loaded
May 2619627 loaded
Jun 2620628 loaded
Jul 2612718 loaded
Aug 26144 loaded
03

What exists inside the category

One item may contain more than one feature.

Runtime identity and credentials

22 · 8.6%

Sandboxing and isolation

95 · 37.3%

Authorization and policy

34 · 13.3%

Audit and approval

33 · 12.9%

Recovery and containment

7 · 2.7%

Monitoring and detection

45 · 17.6%

04

Representative projects

05

Cross-source validation

These publications are not part of the primary numeric cohort.