Tools & References
Tools & References
This section is the reference shelf for the rest of the site. The Roadmap explains why and what; the Labs show how, step by step; this section answers “which tool do I reach for, and where do I read the primary source?”
Nothing here is a tutorial. Each entry gives you the name, the link, a one-line description, an install command where one exists, and — most importantly — a line on why it matters for agent security specifically.
If you are working through the 90-Day Plan, you do not need most of this at once. Month 1 needs Python and one model SDK. Month 2 adds an orchestration framework and MCP. Month 3 is where the red team and observability tooling earns its place.
What’s here
LangGraph, CrewAI, AutoGen, MCP, local inference, vector stores
garak, PyRIT, promptfoo, Giskard, ART, guardrail libraries
OpenTelemetry, tracing backends, OPA, signing, SBOM
Official framework, standard, and regulatory sources
How to use this section
- Read the concept in the Roadmap first, so you know what problem the tool solves.
- Come here for the install command and the security-relevant caveat.
- Run the corresponding Lab to see it working on something you built.
- When you write up a finding, cite the primary source from Standards & References — not a blog summary, and not this site.
Every tool and standard listed here is an external project or an official publication. Versions, install commands, URLs, licenses, and document numbers change without notice, and framework releases are versioned. Always confirm against the linked source before relying on anything here in a deliverable.