GuardLink
Embeds security annotations directly in source code to maintain living threat models that update with code changes, enforced throu
GuardLink keeps threat models current by storing security decisions as structured annotations in source code comments. Developers and AI coding agents annotate routes, database queries, and authentication flows with threat and mitigation metadata using a 16-verb grammar that covers assets, threats, controls, data flows, and trust boundaries. The built-in MCP server gives AI agents tools to parse the threat model, validate annotations, suggest new ones, and generate reports using frameworks like STRIDE, DREAD, and PASTA. CI integration validates annotations on every PR, diffs threat models between git refs, blocks unmitigated exposures, and exports findings as SARIF for GitHub Advanced Security. Multi-repo workspaces link services so the threat model spans microservice boundaries.
Source
Repository: https://github.com/bugb-technologies/guardlink
Maintain GuardLink?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[GuardLink on getagentictools](https://getagentictools.com/mcp/bugb-technologies-guardlink?ref=badge)