Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Resources

Documentation lives with the code

Install guides, API reference and deployment notes are versioned alongside the packages they describe, so they stay correct. These are the entry points.

  • cerberus-core ↗

    The open core: guard() around your tool executor, the detection layers, and the provenance ledger. Installation, configuration and framework adapters.

    MIT · GitHub

  • @cerberus-ai/core on npm ↗

    The published package. Runtime security for AI agent tool execution — detects, correlates and interrupts guarded Lethal Trifecta attack paths.

    npm

  • Cerberus product page

    What the runtime does, the editions, and the measured evidence with its methodology stated alongside it.

    Product

  • argus-core ↗

    The open core of the autonomous red-team engine for LLM and agent targets.

    MIT · GitHub

  • ARGUS validation benchmarks ↗

    Nineteen intentionally vulnerable agent targets with canary-based win conditions, for evaluating offensive tooling against something other than your own product.

    Apache-2.0 · GitHub

  • ttp-lab ↗

    Reproduce the published read-relevance gate study from seed, or run the mechanism over your own agent-memory traces.

    MIT · GitHub

  • cerberus-action ↗

    A GitHub Action that tests one agent workflow for dangerous tool-execution paths on every pull request.

    MIT · GitHub Action

  • cerberus-mcp-tool-scan ↗

    A GitHub Action that scans agent and MCP tool descriptions for hidden or malicious instructions before they reach a model.

    MIT · GitHub Action

  • TraceLock product page

    Continuous control monitoring, the framework crosswalk, and what an auditor can verify independently.

    Product

  • Glossary

    Definitions for the terms used across the documentation and the product pages.

    Reference

Need help getting it into production?

Warden's deployment practice does the runtime rollout, the integration work and the enablement — the same engineers who maintain these packages.