{
  "$schema_doc": "https://gtmstacker.com/registry/schema/entry.schema.json",
  "stability": "emerging",
  "generator": "agentic-media-registry",
  "generated_at": "2026-09-28T00:00:00Z",
  "id": "com.gtmstacker.registry/tool/openappa",
  "type": "tool",
  "slug": "openappa",
  "canonical_url": "https://gtmstacker.com/registry/tool/openappa/",
  "title": "OpenAPPA",
  "description": "OpenAPPA is a deterministic guardrail layer that intercepts agent tool calls and verifies data flows against declarative policies, blocking data exfiltration from prompt injection or hallucination without breaking agent function. Open source: yes (MIT); self-hostable; pricing free. Runs in-process; 26 stars; active.",
  "category": "mcp-agents",
  "tags": [
    "mcp-agents",
    "agent-security",
    "prompt-injection",
    "data-exfiltration",
    "guardrails",
    "self-hostable"
  ],
  "status": "active",
  "revision": 1,
  "content_hash": "4bd603d6bae349de61607e4c0112cfd33110a7189712c501f2af9d07c7fae9eb",
  "date_published": "2026-09-28T00:00:00Z",
  "date_modified": "2026-09-28T00:00:00Z",
  "source": {
    "name": "archestra-ai · GitHub",
    "url": "https://github.com/archestra-ai/openappa"
  },
  "license": "MIT",
  "one_liner": "OpenAPPA intercepts agent tool calls and checks their data flows against declarative policies, blocking exfiltration from prompt injection or hallucination.",
  "open_source": "yes",
  "self_hostable": "yes",
  "pricing_model": "free",
  "who_its_for": "An engineer giving an agent tools that touch sensitive data who wants a deterministic, policy-driven check on the data FLOW — what leaves and where it goes — rather than a probabilistic injection classifier, and who can run the guard in-process alongside the agent.",
  "who_its_not_for": "Teams wanting a hosted, managed security service, or those unwilling to author declarative data-flow policies up front.",
  "aliases": [
    "openappa",
    "open appa",
    "archestra-ai/openappa"
  ],
  "alternatives": [
    "provenance-gate",
    "chimera",
    "agent-governance-toolkit"
  ],
  "secondary_categories": [
    "ai-infrastructure"
  ],
  "last_verified": "2026-09-28",
  "evidence": {
    "claim_type": "vendor-claim",
    "source_id": "https://github.com/archestra-ai/openappa",
    "note": "MIT per repo; 26 stars; 668 commits; runs in-process; intercepts tool calls and verifies data flows against declarative policies. Vendor (Archestra AI) reported: successful attacks 0% (OpenAPPA) vs 10% (Claude auto-mode) and 31% (FIDES); task completion 89% vs 90% and 41% respectively (github.com/archestra-ai/openappa + openappa.com, verified 2026-09-28)."
  },
  "caveats": "Verified from the primary repo and openappa.com (2026-09-28); no independent testing here. The 0%-attack / 89%-completion figures against Claude auto-mode (10% / 90%) and FIDES (31% / 41%) are the vendor's own benchmark (vendor-claim), not independently reproduced — reproduce on your own tools and data before trusting the numbers. At 26 stars this is young; the policy layer is only as good as the policies you write.",
  "lead": "OpenAPPA is a deterministic guardrail layer that intercepts agent tool calls and verifies data flows against declarative policies, blocking data exfiltration from prompt injection or hallucination without breaking agent function. Open source: yes (MIT); self-hostable; pricing free. It runs in-process, has 26 stars, and is active (668 commits).",
  "chunks": [
    {
      "index": 0,
      "heading_path": [],
      "est_tokens": 87,
      "text": "OpenAPPA is a deterministic guardrail layer that intercepts agent tool calls and verifies data flows against declarative policies, blocking data exfiltration from prompt injection or hallucination without breaking agent function. Open source: yes (MIT); self-hostable; pricing free. It runs in-process, has 26 stars, and is active (668 commits)."
    },
    {
      "index": 1,
      "heading_path": [
        null,
        "What it does"
      ],
      "est_tokens": 248,
      "text": "OpenAPPA is a deterministic guardrail layer that intercepts agent tool calls and verifies data flows against declarative policies, blocking data exfiltration from prompt injection or hallucination without breaking agent function. Open source: yes (MIT); self-hostable; pricing free. It runs in-process, has 26 stars, and is active (668 commits).\n\nOpenAPPA sits between an agent and its tools and reasons about data movement rather than message text. When the agent tries to call a tool, OpenAPPA checks the data flow that call would create against declarative policies — what data is leaving, and to where — and deterministically blocks flows that would exfiltrate sensitive data, whether the trigger was a prompt injection or a plain hallucination. The stated design goal is to do this without breaking the agent's legitimate function: block the leak, keep the task working. It runs in-process alongside the agent (no separate service). Open source: yes (MIT); self-hostable; pricing free."
    },
    {
      "index": 2,
      "heading_path": [
        null,
        "Provenance"
      ],
      "est_tokens": 217,
      "text": "sensitive data, whether the trigger was a prompt injection or a plain hallucination. The stated design goal is to do this without breaking the agent's legitimate function: block the leak, keep the task working. It runs in-process alongside the agent (no separate service). Open source: yes (MIT); self-hostable; pricing free.\n\n- MIT per repo; 26 stars; 668 commits; in-process; intercepts tool calls and verifies data flows against declarative policies (github.com/archestra-ai/openappa + openappa.com, verified 2026-09-28).\n- Vendor (Archestra AI) benchmark: successful attacks 0% vs 10% for Claude auto-mode and 31% for FIDES; task completion 89% vs 90% and 41%. Stated here as the vendor's own numbers (vendor-claim), not independently reproduced.\n- Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28."
    },
    {
      "index": 3,
      "heading_path": [
        null,
        "Why it matters for a GTM stack"
      ],
      "est_tokens": 279,
      "text": "2026-09-28). - Vendor (Archestra AI) benchmark: successful attacks 0% vs 10% for Claude auto-mode and 31% for FIDES; task completion 89% vs 90% and 41%. Stated here as the vendor's own numbers (vendor-claim), not independently reproduced. - Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28.\n\nA GTM agent with CRM, inbox, and enrichment access holds exactly the data an exfiltration attack wants — and the dangerous failure is not a wrong answer but a correct-looking tool call that ships that data somewhere it should not go. OpenAPPA targets that class deterministically: it gates on the data flow the call produces, not on spotting the injecting text, and aims to keep legitimate work flowing. Open source: yes (MIT); self-hostable; pricing free. The honest read: the vendor's headline (0% attacks, 89% task completion, beating Claude auto-mode and FIDES) is its own benchmark and the project is young at 26 stars — the mechanism is well-aimed, but pilot it on your own sensitive tools and write real policies before trusting it in front of live data."
    }
  ],
  "alternates": {
    "markdown": "https://gtmstacker.com/registry/tool/openappa/index.md",
    "html": "https://gtmstacker.com/registry/tool/openappa/",
    "json": "https://gtmstacker.com/registry/tool/openappa/index.json",
    "server_json": "https://gtmstacker.com/registry/tool/openappa/server.json"
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "WebSite",
        "@id": "https://gtmstacker.com/#website",
        "url": "https://gtmstacker.com/",
        "name": "GTM Stacker Agent Registry",
        "description": "A daily-updated, agent-native registry of open-source tool discoveries, tool updates, and curated news for the go-to-market / RevOps engineering niche. Machine-readable first: agents can discover, parse, page, and delta-sync it without scraping HTML.",
        "inLanguage": "en",
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "Organization",
        "@id": "https://gtmstacker.com/#organization",
        "name": "GTM Stacker",
        "url": "https://gtmstacker.com",
        "description": "The growth-systems practice of Theo Popov: AI-native enrichment, outbound, content engines and internal tooling for startups and venture programs. Its agent-native media property, the GTM Stacker Agent Registry, maintains a daily-updated catalog of open-source go-to-market and RevOps tools that both people and AI engines can discover, compare, and cite.",
        "foundingDate": "2024-08",
        "knowsAbout": [
          "go-to-market engineering",
          "RevOps",
          "sales automation",
          "marketing operations",
          "open-source software",
          "AI agents"
        ],
        "founder": {
          "@type": "Person",
          "@id": "https://gtmstacker.com/#founder",
          "name": "Theo Popov",
          "jobTitle": "Growth Operations & GTM Systems",
          "url": "https://gtmstacker.com/about/",
          "sameAs": [
            "https://www.linkedin.com/in/theo-popov",
            "https://x.com/Theo_Popov",
            "https://github.com/theopopov"
          ],
          "worksFor": {
            "@id": "https://gtmstacker.com/#organization"
          }
        },
        "sameAs": [
          "https://www.linkedin.com/company/gtmstacker",
          "https://www.youtube.com/@gtmstacker",
          "https://www.instagram.com/gtmstacker/",
          "https://www.tiktok.com/@gtmstacker"
        ],
        "mainEntityOfPage": "https://gtmstacker.com/registry/about/"
      },
      {
        "@type": "SoftwareApplication",
        "@id": "https://gtmstacker.com/registry/tool/openappa/#software",
        "name": "OpenAPPA",
        "identifier": "archestra-ai/openappa",
        "description": "OpenAPPA is a deterministic guardrail layer that intercepts agent tool calls and verifies data flows against declarative policies, blocking data exfiltration from prompt injection or hallucination without breaking agent function. Open source: yes (MIT); self-hostable; pricing free. Runs in-process; 26 stars; active.",
        "applicationCategory": "DeveloperApplication",
        "url": "https://gtmstacker.com/registry/tool/openappa/",
        "datePublished": "2026-09-28T00:00:00Z",
        "dateModified": "2026-09-28T00:00:00Z",
        "isPartOf": {
          "@id": "https://gtmstacker.com/#website"
        },
        "softwareHelp": "https://www.openappa.com/",
        "license": "https://spdx.org/licenses/MIT.html",
        "codeRepository": "https://github.com/archestra-ai/openappa",
        "keywords": "mcp-agents, ai-infrastructure, agent-security, prompt-injection, data-exfiltration, guardrails, self-hostable",
        "author": {
          "@type": "Organization",
          "name": "archestra-ai",
          "url": "https://github.com/archestra-ai",
          "sameAs": [
            "https://github.com/archestra-ai/openappa",
            "https://www.openappa.com/"
          ]
        },
        "offers": {
          "@type": "Offer",
          "price": 0,
          "priceCurrency": "USD"
        },
        "isSimilarTo": [
          {
            "@type": "SoftwareApplication",
            "name": "Provenance Gate",
            "url": "https://gtmstacker.com/registry/tool/provenance-gate/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "Chimera",
            "url": "https://gtmstacker.com/registry/tool/chimera/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          },
          {
            "@type": "SoftwareApplication",
            "name": "Agent Governance Toolkit",
            "url": "https://gtmstacker.com/registry/tool/agent-governance-toolkit/",
            "applicationCategory": "DeveloperApplication",
            "offers": {
              "@type": "Offer",
              "price": 0,
              "priceCurrency": "USD"
            }
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "@id": "https://gtmstacker.com/registry/tool/openappa/#breadcrumb",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "GTM Stacker Registry",
            "item": "https://gtmstacker.com/registry/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "MCP Agents",
            "item": "https://gtmstacker.com/registry/category/mcp-agents/"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "OpenAPPA",
            "item": "https://gtmstacker.com/registry/tool/openappa/"
          }
        ]
      }
    ]
  },
  "tool": {
    "name": "archestra-ai/openappa",
    "repository": {
      "url": "https://github.com/archestra-ai/openappa",
      "source": "github"
    },
    "homepage": "https://www.openappa.com/"
  }
}
