Network-AI
Frameworks & Eval · tested 2026-08-07 · re-test due 2026-11-07 · by the Hlido desk, not the vendor
In short: A governance layer for multi-agent systems that names the real failure mode — agents don't crash, they silently overwrite each other — and discloses its own high-severity CVEs on the front page.
5 PASS · 0 FAIL of 5 public-surface claims
Quick answer
Network-AI scores 76/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-07). STEADY (76) for a correctly-identified and under-served problem, primitives that actually address it (mutex-backed propose/validate/commit, permission gating, tamper-evident audit log), MIT licensing, and conspicuous sec Pricing: Open source (free entry point documented).
Network-AI sits between agents and shared state, adding locking, permission gating, budgets, audit trails and workflow governance so parallel agent systems behave like production software. The problem statement is the sharpest in this wave: parallel agents "do not usually fail loudly — they fail by silently overwriting state, bypassing policy, drifting across workflow stages, and leaving you with no reliable audit trail." That is correct, under-discussed, and exactly what most orchestration frameworks assume away. The primitives match it: propose→validate→commit with a filesystem mutex instead of last-write-wins, permission scoring before sensitive operations, and an append-only HMAC/Ed25519 tamper-evident audit log. It wraps existing agents (LangChain, CrewAI, AutoGen, MCP) rather than replacing them. What raises confidence most is uncomfortable: the release snapshot on the homepage is v5.15.1, headlined "Security: ClaudeHookBridge & SandboxPolicy matcher bypass fixes — two high-severity vulnerabilities." A security-governance product publishing its own high-severity bypasses on its landing page is behaving the way we want vendors to behave, and it also tells you the product is young enough to have shipped two policy-bypass bugs in consecutive releases. 3,638 tests across 41 suites and 32 adapters are self-reported and unverified. MIT licensed. Reviewed from the public surface.
Why STEADY
STEADY (76) for a correctly-identified and under-served problem, primitives that actually address it (mutex-backed propose/validate/commit, permission gating, tamper-evident audit log), MIT licensing, and conspicuous security honesty — it publishes its own high-severity fixes rather than burying them. Held below VITAL because those same disclosures show policy-bypass bugs in consecutive recent releases, every metric (3,638 tests, 32 adapters) is self-reported, and there is no third-party audit of a component whose entire value is enforcement.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — 'Orchestrate agents without trusting them blindly.'
- PASS Cta present (required) — 'Read quick start' / 'Security posture'
- PASS Pricing or access — MIT licensed, open source, npm-distributed
- PASS Evidence or demo — Release notes with security disclosures, demos and journal; metrics self-reported
What we saw
4 screenshots captured by the Hlido engine during the reviewed run (run-be5ebff148cf15a4-network-ai-org). Our own captures — not vendor marketing material.
What it does well
- Names the real multi-agent failure mode — silent state overwrites and policy bypass, not loud crashes
- propose → validate → commit with a filesystem mutex instead of last-write-wins races
- Permission-first execution: scores justification quality, trust level and resource risk before sensitive operations
- Append-only HMAC / Ed25519 audit log — tamper-evident by design
- Wraps existing frameworks (LangChain, CrewAI, AutoGen, MCP) rather than demanding a rewrite
- Publishes its own high-severity security fixes on the landing page instead of hiding them
- MIT licensed with zero adapter runtime dependencies
What it fails at
- Its own disclosures show two high-severity policy-bypass vulnerabilities across consecutive releases — young enforcement code
- 3,638 tests / 41 suites / 32 adapters are all self-reported and unverified by us
- No third-party security audit, for a product whose entire value proposition is enforcement
- No named production users or adoption figures
- Adds a mandatory layer between agents and state — a new dependency in the critical path
- Not exercised by us; the locking and gating guarantees are untested
Red flags
- [object Object]
Best for
- Teams running genuinely parallel agents against shared state who have hit silent overwrites
- Regulated contexts needing a tamper-evident record of what an agent was permitted to do
- Multi-framework estates wanting one governance layer rather than per-framework controls
Not recommended for
- Single-agent or strictly sequential workflows, where the coordination cost buys nothing
- Deployments requiring an audited enforcement layer today
- Teams unable to absorb frequent security-driven upgrades
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
- Pricing findable on the public surfacePASS MIT licensed, open source, npm-distributed (tested 2026-08-05)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-05.
Related agents
Agent relevance
API MCP SDK Behavioral-testable
Agentic-Commerce Readiness 77/100 · COMMERCE-READY
Independent readiness for agent delegation & transaction. How it’s scored · check live
Purpose-built to sit in the agent execution path: adapters for LangChain, CrewAI, AutoGen and MCP, with control primitives (Blackboard, AuthGuardian, JourneyFSM, budgets) that agents call rather than humans.
Agent-friendly score: 9/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Multi-agent control plane adding locking, permission gating, budgets and audit trails — source (2026-08-07) verified
- propose → validate → commit with a filesystem mutex — source (2026-08-07) verified
- Append-only HMAC / Ed25519 tamper-evident audit log — source (2026-08-07) verified
- v5.15.1 fixes two high-severity ClaudeHookBridge / SandboxPolicy bypasses — source (2026-08-07) verified
- 32 adapters, 3,638 tests, 41 suites, MIT licensed — source (2026-08-07)
- Third-party security audit or named production users — source (2026-08-07)



