01Secure credential management, injecting secrets at the last mile encrypted at rest
02Content inspection to scan requests and responses for secrets, PII, and prompt injection
03Policy enforcement with YAML-based rules, glob patterns, and hot-reload
041 GitHub stars
05Tamper-evident audit logging with blake3 hash chains for all agent actions
06Token-bucket rate limiting per session, operator, tool, or globally with cost tracking