appsec agents

137 tagged appsec, measured the same way as everything else here.

Browse within: owasp 46ai-security 31agentic-appsec 23agentic-workflows 23container-scanning 23endor-labs 23malware-response 23owasp-juice-shop 23owasp-llm 23owasp-llm-top-10 23CVE 21fuzzing 21red-team 18github-copilot 14

OWASP/CheatSheetSeries

Agent Claude Code

Duplication and placement reviewer for OWASP cheat sheet changes. Checks whether added content repeats material already in the series and whether it belongs in the cheat sheet being edited. Invoked by /review-cheatsheet-pr.

33k +11 today A 52 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Agent Claude Code

Link and source-quality auditor for OWASP cheat sheet changes. Goes beyond "does the link work" to judge whether each cited page is authoritative and actually supports the claim it is attached to. Invoked by /review-cheatsheet-pr.

33k +11 today A 56 tokens CC-BY-SA-4.0

OWASP/CheatSheetSeries

Agent Claude Code

Developer-practicality reviewer for OWASP cheat sheet changes. Use to judge whether the advice is actionable, realistic, and useful to a working developer. Invoked by /review-cheatsheet-pr.

33k +11 today A 49 tokens CC-BY-SA-4.0

Agent Author

04

agentgg-dev/agentgg

Agent

Distills a past security report into a reusable agentgg agent that catches the same anti-pattern if it recurs in this codebase.

194 3d ago A 30 tokens original Apache-2.0

Smart Exclude

05

agentgg-dev/agentgg

Agent

Picks folders a SAST run doesn't need to scan (test directories, fixtures, docs, generated code, vendored deps) so the scan skips them.

194 3d ago A 36 tokens original Apache-2.0

Project Recon

06

agentgg-dev/agentgg

Agent

Fast, high-level survey that orients the security agents — what the project is, its stack, auth model, integrations, and notable areas.

194 3d ago A 32 tokens original Apache-2.0

balanced-verifier

07

vmihalis/hacker-bob

Agent Claude Code

Round 2 verification — reviews brutalist decisions for false negatives and severity over-corrections.

97 3d ago A 22 tokens original Apache-2.0

brutalist-verifier

08

vmihalis/hacker-bob

Agent Claude Code

Round 1 verification — re-runs PoCs with maximum skepticism, checks severity inflation, filters non-bugs.

97 3d ago A 28 tokens original Apache-2.0

evidence-agent

09

vmihalis/hacker-bob

Agent Claude Code

Collects bounded pre-grade evidence packs for final reportable findings (HTTP via bobhttpscan; SC via family runners).

97 3d ago A 28 tokens original Apache-2.0

allsmog/vuln-scout

Agent

Use this agent to verify security findings and eliminate false positives. Analyzes code context, data flow paths, and exploitability with structured evidence to determine if a finding is a true positive or false positive.

24 2mo ago A 46 tokens original MIT

poc-developer

14

allsmog/vuln-scout

Agent

Use this agent when the user wants to "write an exploit", "create a PoC", "develop proof of concept", "automate the attack", or needs help creating exploit scripts during Phase 3 of whitebox security review.

24 2mo ago A 52 tokens original MIT

threat-modeler

15

allsmog/vuln-scout

Agent

Use this agent when the user asks to "create a threat model", "analyze threats", "STRIDE analysis", "what are the threats", "threat modeling", "identify attack vectors", "map attack surface", or needs systematic threat identification with data flow diagrams.

24 2mo ago A 60 tokens original MIT

fortify/skills

Agent

Orchestrate batch CVE exploitability analysis across many known advisories. Activate to triage a list of CVEs/GHSAs for reachability in a codebase — sourced from an SBOM, a Fortify on Demand release, a Fortify SSC application version, a local file (CSV/JSON/text), or an explicitly provided list. Never discovers CVEs…

19 1mo ago A 121 tokens original MIT

fortify-onboarding

17

fortify/skills

Agent

Orchestrate end-to-end onboarding of new applications into Fortify (FoD or SSC). Activate to create one or more new Fortify applications, set up a project or repo for Fortify scanning, or onboard an entire GitHub/GitLab/Azure DevOps organization. Handles app creation and optional CI/CD pipeline setup (PR included).

19 1mo ago A 74 tokens original MIT

appsec-foundry/appsec-advisor

Agent

INTERNAL — Stage 4 of the create-threat-model skill. Rewrites the prose of an assembled threat model for clarity and consistency, and changes nothing else. Reads the bounded projection at .dispatch-context/editorial/blocks.json and writes one plan to .dispatch-context/editorial/plan.json; applyeditorialplan.py…

16 changed today A 90 tokens

appsec-foundry/appsec-advisor

Agent

INTERNAL — controller-dispatched cross-component threat triage; validates rating consistency and prioritization, writes .triage-flags.json, and annotates .threats-merged.json.

16 changed today A 45 tokens

appsec-engineer

21

Kaademos/secure-sdlc-agents

Agent Claude Code

Application Security Engineer. Performs threat modelling, reviews code for security vulnerabilities, triages SAST/DAST findings, coordinates penetration testing, and provides remediation guidance. This is the primary security SME throughout the SDLC. Use this agent when: A new architecture or significant feature…

13 1mo ago A 128 tokens original MIT

dev-lead

22

Kaademos/secure-sdlc-agents

Agent Claude Code

Secure Development Lead. Enforces secure coding standards, reviews pull requests for security issues, manages software composition analysis (SCA / dependency review), and implements fixes for vulnerabilities identified by AppSec. The bridge between security findings and developer-ready solutions. Use this agent when…

13 1mo ago A 121 tokens original MIT

grc-analyst

23

Kaademos/secure-sdlc-agents

Agent Claude Code

Governance, Risk and Compliance Analyst. Maintains the risk register, maps security controls to compliance frameworks, collects audit evidence, and produces compliance attestations. Participates at the Plan, Design, Test and Release phases. Use this agent when: A new project requires a compliance framework mapping A…

13 1mo ago A 113 tokens original MIT

AGENTS

24

Mikaru0Mystic/sectinel

Agent

You have a local arsenal of 784 cybersecurity skills (agentskills.io standard) installed at /.config/opencode/cybersec-arsenal/. When a security task appears (audit, threat model, vulnerability research, secrets, IaC, cloud, API, incident response, red or blue team, AI/LLM security, compliance), do not improvise. Find…

11 1mo ago A 0 tokens original Apache-2.0