Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
nexus-os — The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP | Kitploit
Tools/GitLabGitLab/nexaiceo/nexus-os
Authentication & AuthorizationCryptographyCloud SecurityDevSecOpsPrivacySupply Chain SecurityMachine LearningLearning & EducationCurated ResourcesAI SecurityLabs & Practice
224 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitLab
nexaiceo/nexus-os

nexus-os

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

View Repository

pipeline status

Nexus OS

The Governed Agentic AI Operating System

66 Crates | 675 Commands | 86 Pages | 5,229 Tests | 10/10 OWASP | Zero Stubs

Local-first. Air-gappable. Post-quantum ready. Built in Rust.

MIT License Rust Tauri 2.0 Tests OWASP v10.6.0

Architecture | Quick Start | Features | Audit Status | Docs


Nexus OS is an AI agent operating system where agents are first-class citizens with cryptographic identities, governed autonomy, and the ability to evolve. It runs entirely on your hardware — no cloud dependency, no data leaving your machine, air-gappable. Every action is hash-chained, every decision auditable, every agent sandboxed.

┌──────────────────────────────────────────────────────────────────────┐
│                        Nexus OS v10.6.0                              │
│                                                                      │
│  ┌──────────┐  ┌──────────┐  ┌──────────┐  ┌──────────┐            │
│  │ Coder    │  │ Research │  │ Security │  │ DevOps   │  ...55     │
│  │ Agent    │  │ Agent    │  │ Agent    │  │ Agent    │  agents    │
│  └────┬─────┘  └────┬─────┘  └────┬─────┘  └────┬─────┘            │
│       │              │              │              │                  │
│  ┌────▼──────────────▼──────────────▼──────────────▼─────┐           │
│  │              Nexus Conductor (Orchestration)           │           │
│  │       A2A Protocol  ·  MCP Protocol  ·  Swarm          │           │
│  └───────────────────────┬────────────────────────────────┘           │
│                          │                                            │
│  ┌───────────────────────▼────────────────────────────────┐           │
│  │                   Governance Kernel                     │           │
│  │  Capability ACL · HITL Gates · Fuel Metering            │           │
│  │  OWASP 10/10 · Ed25519 Consent · PII Redaction          │           │
│  │  Hash-Chain Audit · WASM Sandbox · Cedar Policies        │           │
│  └───────────────────────┬────────────────────────────────┘           │
│                          │                                            │
│  ┌───────────────────────▼────────────────────────────────┐           │
│  │                    LLM Providers (15)                    │           │
│  │  Ollama · OpenAI · Claude · Gemini · Groq · DeepSeek    │           │
│  │  NVIDIA NIM · OpenRouter · Mistral · Cohere · Fireworks  │           │
│  │  Together · Perplexity · Flash (llama.cpp) · + Mock      │           │
│  └────────────────────────────────────────────────────────┘           │
│                                                                      │
│  Rust Kernel (326K LOC) · Tauri 2.0 Shell · React/TS Frontend (65K)  │
└──────────────────────────────────────────────────────────────────────┘

Why Nexus OS?

ProblemEveryone ElseNexus OS
Data sovereigntySend everything to the cloud100% local-first, air-gappable
Agent safetyTrust the agent, hope for the bestWASM sandbox, capability ACL, fuel limits
Agent identityAnonymous function callsEd25519 cryptographic identity per agent
Audit trailLogs (deletable, mutable)Hash-chained audit trail (tamper-evident)
Human oversightOptional, bolted onHITL consent gates built into kernel
Agent evolutionStatic prompts foreverDarwinian evolution: agents mutate, compete, improve
Compliance"We're working on it"EU AI Act conformity, OWASP Agentic 10/10
PerformancePython + ElectronRust kernel + Tauri 2.0 (5MB binary vs 100MB+)
Vendor lock-inPick one cloud provider15 LLM providers, 200+ models, swap freely or go offline
Security standardAd-hocOWASP Agentic Top 10 — all 10 defenses with 62 tests

Features

Governance and Security

  • OWASP Agentic Top 10 — All 10 defenses implemented and tested (62 dedicated tests)
  • Ed25519 consent signing — Tier2+ approvals are cryptographically non-repudiable
  • Post-quantum ready — Ed25519 + X25519 with ML-DSA/ML-KEM roadmap (nexus-crypto)
  • Prompt firewall — 20 injection patterns, PII redaction, output filtering
  • Cedar-inspired policies — Declarative capability rules with formal evaluation
  • HITL consent gates — 4 tiers (Tier0-3) with configurable approval counts
  • Hash-chained audit — Tamper-evident, append-only, cryptographically verifiable
  • Checkpoint-rollback — 3-level recovery: memory, execution, side-effect compensation

Agent Intelligence

  • Cognitive loop — Perceive, reason, plan, act, reflect, learn cycle
  • Darwin Core — Adversarial arena, swarm coordination, evolutionary strategies
  • Capability measurement — 4-vector scoring with gaming detection
  • Predictive routing — Model selection optimized for latency, cost, and task complexity
  • Memory subsystem — 4 types (working, episodic, semantic, procedural) with SQLite, GC, rollback, ACL
  • 55 prebuilt agents across 7 autonomy levels (L0-L6)

Protocols and Integration

  • MCP — JSON-RPC 2.0 client with subprocess tool discovery
  • A2A — Agent-to-agent discovery, task delegation, status tracking
  • OpenAI-compatible REST API — Chat completions, tool calls, SSE streaming
  • Messaging adapters — Slack, Discord, Matrix, Telegram, WhatsApp, Webhook
  • Migration tool — Import from CrewAI and LangGraph

Infrastructure

  • Token economy — Wallets, fuel metering, delegation contracts, tier gating
  • Software factory — Project creation, build pipeline, quality gates
  • Marketplace — Ed25519 signed packages with verification pipeline
  • World simulation — Virtual filesystem sandbox with dry-run and risk assessment
  • Collaboration protocol — Multi-agent sessions with voting and consensus

Governed Self-Improvement

  • 5-stage pipeline — Observer, Analyzer, Proposer, Validator, Applier
  • 10 hard invariants — Governance kernel immutable, HITL Tier3 required, audit chain integrity
  • DSPy/OPRO prompt optimizer — Variant generation, safety keyword enforcement, cosine similarity scoring
  • Config optimizer — 8 tunable parameters with bounded step-size adjustments
  • Policy optimizer — Cedar policy refinement (can only narrow, never broaden)
  • Behavioral envelope — Drift Bounds Theorem (D* = alpha/gamma) bounds agent drift
  • Simplex guardian — Verified-safe baseline with barrier certificate switching
  • 182 tests + 7,424 property-generated cases

Desktop and Local-First

  • Flash inference — llama.cpp via FFI, GGUF loading, speculative decoding
  • 15 LLM providers — All with real HTTP calls, automatic failover
  • Voice pipeline — Push-to-talk, Whisper transcription, Web Speech API
  • Browser automation — Playwright integration with URL allowlist and financial blocking
  • Computer control — Screen capture, input execution, governance-gated at L4+
  • 86 frontend pages — Full management UI for every subsystem

Flash Inference — Run Any Open-Source Model Locally

Download Tool