The September 2026 open-source security roundup from Help Net Security highlights a broad mix of tools, ranging from secrets discovery to AI infrastructure hardening. Several offerings tackle the growing intersection of AI and security: Tencent's Zhuque Lab released AI-Infra-Guard, which fingerprints services like Ollama and vLLM, checks them against more than 1,600 known CVEs, and evaluates jailbreak risks. Meanwhile, Prismor acts as a runtime control plane for AI coding agents, ruling each tool call allow, warn, or block, and Stacklok's ToolHive runs MCP servers inside containers so AI clients can reach external tools with isolated permissions.

Other tools in the lineup focus on classic security problems. Sift, built by penetration testing consultancy Stratus Security, searches for passwords and API keys across local disk, Active Directory, SharePoint, Teams, Slack, and Jira. DeepZero automates the hunt for exploitable Windows kernel drivers by parsing binaries and using a language model to assess attackability. On the access-control side, Permify and Authorizer both move authorization rules out of application code, with Authorizer also exposing a permissions engine to AI agents.

Because this is a single curated list, there are no conflicting sources to compare, but the collection itself signals a clear trend: open-source security tools are converging on AI supply chains, agent safety, and automated secrets hygiene. All of the tools are free to self-host, reflecting a community push to make enterprise-grade security capabilities available without licensing costs.