Cadence: the resource-oriented smart contract programming language of the Flow network. Capability-based security, type safety, and move semantics
-
Updated
Jul 24, 2026 - Go
Cadence: the resource-oriented smart contract programming language of the Flow network. Capability-based security, type safety, and move semantics
Sandboxed plugin VM with typed capabilities, deterministic replay, and time-travel debugging — written in Rust.
Decentralized OS for multi-tool agent swarms.
InferNode is a security-focused 64-bit Inferno® OS (ARM64/AMD64) for embedded systems, servers, and AI agents. GPL-free, headless-capable, with 280+ utilities and 9P filesystem protocol. Providing a namespace-based alternative to MCP servers. Namespace-bounded security has been formally verified.
Governed AI agent runtime with a local-first desktop app + CLI. Chat with any model (Claude, OpenAI, Groq, Ollama, LM Studio); every action passes Intent → Proposal → Commit through signed capability writs, risk-gated approvals, and a replayable hash-chained ledger. Watch it think in the Mind graph. Cognition proposes; the runtime governs.
Compile-time capability-based security for Rust
Three packages: @kernel.chat/agent-os (POSIX for AI agents — capabilities, namespaces, quotas, taint, audit, vault, outcomes), @kernel.chat/kbot (terminal AI agent, MCP-native, BYOK), @kernel.chat/kbot-finance (audit-grade AI for regulated industries). Provenance-engineering substrate.
The home of the Cadence website
Zero-trust, capability-based Rust microkernel targeting formal verification. Tri-arch (x86_64 / AArch64 / RISC-V). Sovereign and generative: no telemetry, user owns keys and data. Early-stage — see STATUS.md. Inspired by seL4, Hubris, and Redox.
A systems language with compile-time capability enforcement
Aster RPC -- peer-to-peer RPC framework with identity in the connection. Machines authenticate to machines, on behalf of users. Built on iroh QUIC + Apache Fory + capability-based credentials.
Leash — 给 AI Agent 拴上牵绳:能力门控、最小特权、确定性执行的安全脚本语言
A local-first contract layer for cyber-physical systems: identity, capability, granted authority, and declared failure behaviour, composed over the stacks you already run.
The first intent-native operating system 🧠🚀🌌
The markdown coordination layer for agents. One readable timeline where agents claim tasks, post results, and hand off work. You see everything. They never duplicate work.
Semantic substrate for programming languages
Cryptographic identity and delegation for AI agents — UCAN chains, RESTRICT mode (structurally impossible escalation), provably-complete cascade revocation. Single Go binary. Apache 2.0.
An embeddable, sandbox-first symbolic term-rewriting language and runtime in Rust — exact rational arithmetic and a capability sandbox for safely evaluating untrusted scripts.
Multi-version WASI polyfill (preview1/2/3) for browsers and JavaScript runtimes, with Web Platform API host imports for WebAssembly components.
A Rust-based research microkernel operating system for RISC-V, focused on capability-based security, deterministic testing, and a Service-Plane userspace.
Add a description, image, and links to the capability-based-security topic page so that developers can more easily learn about it.
To associate your repository with the capability-based-security topic, visit your repo's landing page and select "manage topics."