OpenAPPA: deterministic AI guardrails that don't break agents
Archestra’s MIT-licensed OpenAPPA sits outside the agent loop and tracks audience×trust labels on data flows instead of regex allowlists, so prompt injection can’t negotiate past it. Their benches show ~89% task completion with 0% successful exfil (vs Claude auto-mode’s ~10% attack success), with Claude Code plugs plus remedy plans, sanitizers, and DualLLM-style subagents when a call is blocked.
