agent-beacon vs numbat
Cross-harness memory for coding agents: captures sessions from Claude Code, Cursor, Codex and 20+ harnesses, distills reviewed knowledge over MCP/skills, and forwards telemetry to SIEMs. — versus — Perplexity's endpoint sensor for AI agents: hooks, OTLP logs and on-disk session artifacts normalized into one CEL-matched event model, with opt-in pre-action blocking and offline forensics.
On the security side both are endpoint sensors normalizing agent hooks, OTLP and session artifacts into one event model; numbat adds CEL matching and pre-action blocking, Beacon forwards to your SIEM and doubles as memory.
| agent-beacon | numbat | |
|---|---|---|
| Stars | 1.7k | 1.1k |
| Forks | 145 | 112 |
| Language | Go | Go |
| License | MIT | Apache-2.0 |
| Last activity | today | 13 days ago |
| Topics | memory, coding, security | security, agents |
| Curated connections | 3 | 8 |
agent-beacon — the curator's take
Two jobs in one endpoint agent, and it pays to know which one you want. The memory side captures every session across Claude Code, Codex, Cursor, OpenCode and 20+ harnesses, replays them exactly, and turns fixes and conventions into reviewed knowledge future agents pull through MCP or Agent Skills. The security side normalizes the same traces into an OpenTelemetry event model and ships them to Splunk, Sentinel, CrowdStrike LogScale and friends, with MSI, .deb/.rpm and MDM installs. Strong fit when a team runs many harnesses and wants one record for both recall and audit. Watch the default: interactive setup preselects hosted Beacon Managed forwarding (Local is an explicit opt-out), so choose deliberately on machines with sensitive code. For solo, single-harness recall, claude-mem or deja-vu is less machinery.
numbat — the curator's take
Think EDR, not guardrails: it sits on the endpoint and watches what the agents on that machine actually did — desktop, CLI, IDE and gateway surfaces alike. Two features earn it the slot. Forensic reconstruction reads session artifacts the agents already wrote, so you can investigate a laptop that never had numbat installed. And enforcement is deliberately awkward to enable: every shipped rule is monitor-only, and blocking requires copying the YAML into your own policy directory, keeping the id, adding `enforce: true` and bumping the version. NOT a prompt-injection classifier and NOT a gateway — it observes and optionally vetoes at supported synchronous pre-action hooks, so check the coverage matrix before assuming your agent has live capture.