Developer releases OpenAPPA to stop AI agents leaking data
OpenAPPA labels data by trust level as AI agents work, blocking exfiltration attempts without the blanket blacklists that its maker says break other agent frameworks.
A developer released OpenAPPA, an open-source tool that tracks how data moves through an AI agent's tool calls. It blocks data from leaving through unauthorized channels, according to the project's site. The tool reached 18 points and seven comments on Show HN within an hour of posting.
The tool runs outside the agent's own execution loop. It reads a declarative configuration file that assigns a security label to data based on its source and trust level, the project says. Labels can only grow more restrictive as data moves through a session, never less. The developer says that makes the system resistant to prompt injection.
When OpenAPPA blocks an action, it returns what its documentation calls a "remedy plan" rather than simply failing. Options include sanitizers that mask sensitive fields, a request for human approval, or routing the read through an isolated subagent. The project is open-source and MIT-licensed. Its developer says it integrates with Archestra and Claude Code.
The project's own benchmark reports 89% task completion with zero successful data-exfiltration attacks. It says that outperforms Microsoft's FIDES on the same test. The comparison is the developer's own measurement, and no independent benchmark of OpenAPPA has been published yet.