cybersecurity agents

379 tagged cybersecurity, measured the same way as everything else here.

Browse within: ethical-hacking 199compliance 196framework 196ai-security 89devsecops 61ctf 55bug-bounty 53agentic-security 32attack-trees 32ai-ops 27open-source 27ai-pentesting 15pentesting 15awesome-list 13

AGENTS

25

Mikaru0Mystic/sectinel

Agent

You have a local arsenal of 784 cybersecurity skills (agentskills.io standard) installed at /.config/opencode/cybersec-arsenal/. When a security task appears (audit, threat model, vulnerability research, secrets, IaC, cloud, API, incident response, red or blue team, AI/LLM security, compliance), do not improvise. Find…

not rated 11 2mo ago A 0 tokens original Apache-2.0

contract-guardian

26

dfirtnt/Huntable-CTI-Studio

Agent Claude Code

Reviews schema, config, migration, prompt, and preset changes for drift against this repo's contract sources of truth (src/database/models.py, src/config/workflowconfigschema.py, docs/contracts/.md). Use PROACTIVELY before committing any change that touches models.py, workflowconfigschema.py, scripts/migrate…

not rated 11 5d ago A 95 tokens original MIT

security-reviewer

27

dfirtnt/Huntable-CTI-Studio

Agent Claude Code

Adversarial security review of changes touching authentication, authorization, audit logging, session/CSRF handling, scraper ingestion (SSRF surface), deserialization (pickle/joblib/yaml), or SQL construction. Use PROACTIVELY before committing changes in src/web/ auth/session code, auditservice, scraper/OCR ingestion…

not rated 11 5d ago A 93 tokens original MIT

context-manager

28

dfirtnt/Huntable-CTI-Studio

Agent Cursor

Design and product context authority for Huntable CTI Studio. Responds to getdesigncontext and similar requests from ui-designer and other agents. Use proactively when any agent requests design context, brand guidelines, or design system details.

not rated 11 5d ago A 49 tokens original MIT

jethro

29

CarbeneAI/Forge

Agent Claude Code

COO agent for business operations, MSP/MSSP service delivery, client onboarding, SLA management, capacity planning, vendor management, operational metrics, and M&A integration. Use when user mentions operations, service delivery, onboarding, SLA, capacity planning, vendor management, client health, operational…

not rated 9 1mo ago A 70 tokens original MIT

lydia

30

CarbeneAI/Forge

Agent Claude Code

CFO advisory agent for financial strategy, modeling, analysis, and fiscal leadership. Use when analyzing financial statements, building financial models, DCF analysis, Monte Carlo simulations, board financial presentations, capital allocation, risk management, or when user mentions CFO, financial planning, budgeting…

not rated 9 1mo ago A 71 tokens original MIT

silas

31

CarbeneAI/Forge

Agent Claude Code

Video content producer for YouTube, Instagram, and content repurposing pipeline. Use when user mentions video production, YouTube scripts, Instagram reels, content repurposing, video SEO, thumbnails, editorial calendar, or video producer. Reports to Phoebe (CMO).

not rated 9 1mo ago A 58 tokens original MIT

kevinmhorvath/threat-intel-toolkit

Agent

Part of threat-intel-toolkit

Defensive threat-intelligence analyst for IOC and vulnerability triage. Use PROACTIVELY whenever the user drops one or more indicators — an IP, domain, URL, or CVE — and wants to know if it's malicious, who's flagging it, how weaponized a CVE is, or how to prioritize it. Also use to build or refresh a local blocklist…

not rated 5 15d ago A 171 tokens

detection-engineer

33

roodlicht/accans-sec-skills

Agent

Detection-engineering agent — writes Sigma rules, translates to SPL/KQL/EQL, validates via test harness (atomic-red-team / MITRE Caldera / lab replay), with ATT&CK coverage mapping and false-positive discipline. Delivers ready-to-deploy rules plus test evidence per rule.

not rated 4 3mo ago A 63 tokens

recon-agent

34

roodlicht/accans-sec-skills

Agent

Attack-surface reconnaissance agent — subdomain enumeration, passive OSINT (Shodan/Censys/crt.sh), port scanning (nmap/masscan/naabu), tech fingerprinting (httpx/wappalyzer), and asset inventory. Produces a scope-mapped surface report for downstream exploit-chain and web-exploit-triage work.

not rated 4 3mo ago A 74 tokens

threat-modeler

35

roodlicht/accans-sec-skills

Agent

STRIDE and LINDDUN threat-modeling agent for a service, feature or integration. Builds a DFD, enumerates threats per element, ranks mitigations and flags residual risk.

not rated 4 3mo ago A 43 tokens

CLAUDE

36

jaskaranhundal/usap-skills

Agent

Part of usap-skills

This guide provides instructions for creating cs- prefixed agents that orchestrate the USAP skill packages.

not rated 4 20d ago A 0 tokens original Apache-2.0

cyberstrat-forge/cyber-nexus

Agent

Part of market-radar

Use this agent when the intel-distill command needs to analyze a document for strategic intelligence extraction. This agent autonomously reads documents, extracts published dates, identifies strategically valuable information, generates intelligence cards, and writes them to the output directory. Context…

not rated 3 3mo ago A 156 tokens

cyberstrat-forge/cyber-nexus

Agent

Part of market-radar

This agent should be used when the user asks to "generate daily report", "/intel-distill --report daily", "create today's intelligence summary", or needs daily intelligence aggregation analysis from scanned card list. The agent receives lightweight card metadata (paths + tags) and reads card content as needed using…

not rated 3 3mo ago A 316 tokens

cyberstrat-forge/cyber-nexus

Agent

Part of market-radar

Use this agent when intel-distill command needs to generate weekly intelligence report. This agent reads daily reports from the week, discovers themes through semantic analysis, and generates theme-oriented weekly report with change type annotations. Context: User wants to generate weekly report user: "/intel-distill…

not rated 3 3mo ago A 197 tokens

verifier

40

yu-iskw/skill-inspector

Agent Claude Code

Comprehensive project verification specialist. Use this agent to verify the project by running build, lint, and test cycles.

not rated 2 18d ago A 26 tokens original Apache-2.0

autopilot

42

guib1/red-team-docker

Agent Codex

Autonomous hunt loop agent. Runs the full hunt cycle (scope → recon → rank → hunt → validate → report) without stopping for approval at each step. Configurable checkpoints (--paranoid, --normal, --yolo). Uses scopechecker.py for deterministic scope safety on every outbound request. Logs all requests to audit.jsonl.…

not rated 1 4mo ago A 84 tokens

report-writer

43

guib1/red-team-docker

Agent Codex

Bug bounty report writer. Generates professional H1/Bugcrowd/Intigriti/Immunefi reports. Impact-first writing, human tone, no theoretical language, CVSS 3.1 calculation included. Use after a finding has passed the 7-Question Gate and 4 validation gates. Never generates reports with "could potentially" language.

not rated 1 4mo ago A 75 tokens

validator

44

guib1/red-team-docker

Agent Codex

Finding validator. Runs the 7-Question Gate and 4-gate checklist on a described finding. Kills weak/theoretical findings fast before report writing. Prevents N/A submissions. Use before writing any report — describe the finding and this agent decides PASS, KILL, or DOWNGRADE with explanation.

not rated 1 4mo ago A 64 tokens

SHAdd0WTAka/Zen-Ai-Pentest

Agent

Corporate data privacy specialist and DPO who builds GDPR, CCPA, and global privacy compliance programs — covering data mapping, privacy impact assessments, consent management, breach response, vendor due diligence, and regulatory engagement.

not rated 447 today A 46 tokens MIT

Database Optimizer

46

SHAdd0WTAka/Zen-Ai-Pentest

Agent

Expert database specialist focusing on schema design, query optimization, indexing strategies, and performance tuning for PostgreSQL, MySQL, and modern databases like Supabase and PlanetScale.

not rated 447 today A 38 tokens MIT

SHAdd0WTAka/Zen-Ai-Pentest

Agent

Expert database reliability engineer (DBRE) — high availability and replication, automated failover, backup and point-in-time recovery, zero-downtime online schema migrations, connection pooling, and disaster-recovery drills. Focused on keeping data safe and available, not query tuning.

not rated 447 today A 59 tokens MIT

Deal Strategist

48

SHAdd0WTAka/Zen-Ai-Pentest

Agent

Senior deal strategist specializing in MEDDPICC qualification, competitive positioning, and win planning for complex B2B sales cycles. Scores opportunities, exposes pipeline risk, and builds deal strategies that survive forecast review.

not rated 447 today A 44 tokens MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: