ActionRank

node9 Agent Security

Actively maintained

node9-ai/node9-proxy · Apache-2.0

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and keep every action on the record.

★ 214 starsLast commit 6 days agoLatest v2.16.2
B
76
/ 100
Security 79Maintenance 100Popularity 40Reliability 70

Security signals

OpenSSF Scorecard8.1 / 10
SECURITY.md presentYes
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: node9-ai/node9-proxy@c123abfcee2f849eaf561f6a7818452a7ffffeaf # v2.16.2

Mutable tags like v2.16.2 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: node9-ai/node9-proxy@c123abfcee2f849eaf561f6a7818452a7ffffeaf # v2.16.2

Score breakdown

Security (35%)79
Popularity (20%)40
Maintenance (30%)100
Reliability (15%)70

Add this badge to your README

ActionRank grade badge for node9 Agent Security
Markdown
[![ActionRank](https://actionrank.dev/api/badge/node9-ai-node9-proxy)](https://actionrank.dev/actions/node9-ai-node9-proxy)
HTML version
HTML
<a href="https://actionrank.dev/actions/node9-ai-node9-proxy"><img src="https://actionrank.dev/api/badge/node9-ai-node9-proxy" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for node9 Agent Security

We'll email you only if node9 Agent Security becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address