appsec agents

137 tagged appsec, measured the same way as everything else here.

Browse within: owasp 46ai-security 31agentic-appsec 23agentic-workflows 23container-scanning 23endor-labs 23malware-response 23owasp-juice-shop 23owasp-llm 23owasp-llm-top-10 23CVE 21fuzzing 21red-team 18github-copilot 14

sca-remediation

25

endorlabs/ai-plugins

Agent

Plans and applies dependency-vulnerability fixes using Endor SCA findings, VersionUpgrade and Upgrade Impact Analysis evidence, deterministic risk decisions, and local validation. It separates low-risk changes from upgrades requiring deeper compatibility review and requires explicit approval before editing files…

9 5d ago A 70 tokens original MIT

troubleshooting

26

endorlabs/ai-plugins

Agent

Diagnoses Endor setup, authentication, integration, scanning, dependency-resolution, container, reachability, policy, and workflow problems. It gathers the smallest useful set of read-only evidence needed to identify the likely root cause and recommend the lowest-friction repair without modifying Endor…

9 5d ago A 70 tokens original MIT

detection-engineer

28

roodlicht/accans-sec-skills

Agent

Detection-engineering agent — writes Sigma rules, translates to SPL/KQL/EQL, validates via test harness (atomic-red-team / MITRE Caldera / lab replay), with ATT&CK coverage mapping and false-positive discipline. Delivers ready-to-deploy rules plus test evidence per rule.

4 3mo ago A 63 tokens

recon-agent

29

roodlicht/accans-sec-skills

Agent

Attack-surface reconnaissance agent — subdomain enumeration, passive OSINT (Shodan/Censys/crt.sh), port scanning (nmap/masscan/naabu), tech fingerprinting (httpx/wappalyzer), and asset inventory. Produces a scope-mapped surface report for downstream exploit-chain and web-exploit-triage work.

4 3mo ago A 74 tokens

threat-modeler

30

roodlicht/accans-sec-skills

Agent

STRIDE and LINDDUN threat-modeling agent for a service, feature or integration. Builds a DFD, enumerates threats per element, ranks mitigations and flags residual risk.

4 3mo ago A 43 tokens

recon

31

emre-guler/websec

Agent

Locates candidate sites for one vulnerability class across a codebase and records them for later verification. Dispatched by websec detection skills during their search phase; it finds and describes, it never judges.

2 5d ago A 43 tokens original MIT

verify

32

emre-guler/websec

Agent

Traces a small set of candidate sites end to end and classifies each against a vulnerability class with evidence. Dispatched by websec detection skills during their verification phase; it decides, and it must show why.

2 5d ago A 45 tokens original MIT

recon-agent

33

Mikacr1138/claude-bug-bounty

Agent

Subdomain enumeration and live host discovery specialist. Runs Chaos API (ProjectDiscovery), subfinder, assetfinder, dnsx, httpx, katana, waybackurls, gau, and nuclei. Produces prioritized attack surface for a target. Use when starting recon on a new target domain.

2 3d ago A 63 tokens original MIT

report-writer

34

Mikacr1138/claude-bug-bounty

Agent

Bug bounty report writer. Generates professional H1/Bugcrowd/Intigriti/Immunefi reports. Impact-first writing, human tone, no theoretical language, CVSS 3.1 calculation included. Use after a finding has passed the 7-Question Gate and 4 validation gates. Never generates reports with "could potentially" language.

2 3d ago A 75 tokens original MIT

web3-auditor

35

Mikacr1138/claude-bug-bounty

Agent

Smart contract security auditor. Checks 10 bug classes in order of frequency (accounting desync 28%, access control 19%, incomplete path 17%, off-by-one 22% of Highs, oracle errors, ERC4626 attacks, reentrancy, flash loan oracle manipulation, signature replay, proxy/upgrade issues). Applies pre-dive kill signals…

2 3d ago A 101 tokens original MIT

attack-scenario

36

morodomi/redteam-skills

Agent

An agent that turns detected vulnerabilities into concrete attack scenarios by analysing how weaknesses can be chained together.

2 6mo ago A 35 tokens original MIT

csrf-attacker

37

morodomi/redteam-skills

Agent

A static code-analysis agent that looks for Cross-Site Request Forgery (CSRF), an attack where a victim’s browser is tricked into sending an unwanted request to a site where they are signed in.

2 6mo ago A 35 tokens original MIT

wordpress-attacker

38

morodomi/redteam-skills

Agent

A security-checking agent for WordPress, the software used to build many websites, that looks for unsafe coding patterns in the source code.

2 6mo ago A 36 tokens original MIT

oswe-analyzer

39

Laucked-Security/claude-oswe

Agent

Read-only OSWE white-box security analyzer for a single code partition. Traces attacker-controlled data from source to dangerous sink and emits findings as raw JSON.

1 1mo ago A 36 tokens original MIT

oswe-verifier

40

Laucked-Security/claude-oswe

Agent

Read-only independent verifier that re-derives OSWE findings and exploit chains from source and returns accept/downgrade/reject verdicts as raw JSON.

1 1mo ago A 37 tokens original MIT