# OpenAPPA

> Updated 2026-09-28 · type: tool · category: mcp-agents · status: active · rev 1

OpenAPPA intercepts agent tool calls and checks their data flows against declarative policies, blocking exfiltration from prompt injection or hallucination.

- Open source: yes (MIT)
- Self-hostable: yes
- Pricing model: free
- Best for: An engineer giving an agent tools that touch sensitive data who wants a deterministic, policy-driven check on the data FLOW — what leaves and where it goes — rather than a probabilistic injection classifier, and who can run the guard in-process alongside the agent.
- Not for: Teams wanting a hosted, managed security service, or those unwilling to author declarative data-flow policies up front.
- Last verified: 2026-09-28

- **Canonical:** https://gtmstacker.com/registry/tool/openappa/
- **Source:** [archestra-ai · GitHub](https://github.com/archestra-ai/openappa)
- **Tags:** mcp-agents, agent-security, prompt-injection, data-exfiltration, guardrails, self-hostable
- **Repository:** https://github.com/archestra-ai/openappa

## Is OpenAPPA open source?

Yes, OpenAPPA is open source under the MIT license.

## How much does OpenAPPA cost?

OpenAPPA is free to use.

## Can I self-host OpenAPPA?

Yes, OpenAPPA can be self-hosted (the source is available under the MIT license).

## Alternatives & related

- [Provenance Gate](https://gtmstacker.com/registry/tool/provenance-gate/)
- [Chimera](https://gtmstacker.com/registry/tool/chimera/)
- [Agent Governance Toolkit](https://gtmstacker.com/registry/tool/agent-governance-toolkit/)


---

OpenAPPA is a deterministic guardrail layer that intercepts agent tool calls and verifies data flows against declarative policies, blocking data exfiltration from prompt injection or hallucination without breaking agent function. Open source: yes (MIT); self-hostable; pricing free. It runs in-process, has 26 stars, and is active (668 commits).

## What it does

OpenAPPA sits between an agent and its tools and reasons about data movement rather than message text. When the agent tries to call a tool, OpenAPPA checks the data flow that call would create against declarative policies — what data is leaving, and to where — and deterministically blocks flows that would exfiltrate sensitive data, whether the trigger was a prompt injection or a plain hallucination. The stated design goal is to do this without breaking the agent's legitimate function: block the leak, keep the task working. It runs in-process alongside the agent (no separate service). Open source: yes (MIT); self-hostable; pricing free.

## Provenance

- MIT per repo; 26 stars; 668 commits; in-process; intercepts tool calls and verifies data flows against declarative policies (github.com/archestra-ai/openappa + openappa.com, verified 2026-09-28).
- Vendor (Archestra AI) benchmark: successful attacks 0% vs 10% for Claude auto-mode and 31% for FIDES; task completion 89% vs 90% and 41%. Stated here as the vendor's own numbers (vendor-claim), not independently reproduced.
- Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28.

## Why it matters for a GTM stack

A GTM agent with CRM, inbox, and enrichment access holds exactly the data an exfiltration attack wants — and the dangerous failure is not a wrong answer but a correct-looking tool call that ships that data somewhere it should not go. OpenAPPA targets that class deterministically: it gates on the data flow the call produces, not on spotting the injecting text, and aims to keep legitimate work flowing. Open source: yes (MIT); self-hostable; pricing free. The honest read: the vendor's headline (0% attacks, 89% task completion, beating Claude auto-mode and FIDES) is its own benchmark and the project is young at 26 stars — the mechanism is well-aimed, but pilot it on your own sensitive tools and write real policies before trusting it in front of live data.
