Security agents

3,534 tagged Security, measured the same way as everything else here.

Browse within: claude-code-plugin 193ai-coding 116Autonomous Agents 75ai-security-tool 68appsec 62ai-security 57multi-agent-systems 51offensive-security 51agentic-coding 49agentic 46cybersecurity 45agent-orchestration 41compliance 40bug-bounty 38

localauditor

241

defuse/auditician-temp

Agent Claude Code

File-scoped security auditor; adds ideas to BRAINSTORM.md and creates individual issue files in issues/plausible/.

not rated 57 19d ago A 30 tokens AGPL-3.0

securityprover

242

defuse/auditician-temp

Agent Claude Code

An expert security proof writer to help identify vulnerabilities, informed by (failed) attempts to prove security.

not rated 57 19d ago A 23 tokens AGPL-3.0

kali-service-enum

243

pabpereza/kali-mcp

Agent

Service Enumeration subagent — runs the full protocol-specific playbook against a single discovered port/service. Reads knowledge/protocols/ .md and executes every step.

not rated 57 1mo ago A 33 tokens original MIT

kali-worker

244

pabpereza/kali-mcp

Agent

Generic Kali pentest worker — receives a specific mission from the orchestrator and executes it using the MCP toolkit. All workflow knowledge comes from the orchestrator's prompt, not from internal state.

not rated 57 1mo ago A 38 tokens original MIT

kali

245

pabpereza/kali-mcp

Agent

Kali Linux ethical hacking assistant — performs authorized security assessments using the MCP toolkit exposed by the Kali container.

not rated 57 1mo ago B 21 tokens original MIT

reviewer

246

heyhuynhgiabuu/pi-task

Agent

PROACTIVE — Use after non-trivial edits for an independent read-only audit of correctness, security, regressions, and maintainability with path:line evidence; not before reviewable code exists.

not rated 57 +1 changed today A 39 tokens original MIT

review-agent

248

aws-samples/sample-claude-code-agent-team

Agent ✓ vendor

Code review teammate — analyzes implementations for correctness, security, and maintainability. Communicates directly with implementers for clarifications. Writes structured findings to review.md.

not rated 56 changed today A 35 tokens MIT-0

auth-auditor

249

solygambas/python-openai-projects

Agent Claude Code

Use this agent to perform a focused security audit of authentication-related code (NextAuth v5 credentials + GitHub, email verification, password reset, and profile update flows). It reports only real, validated issues and writes results to docs/audit-results/AUTHSECURITYREVIEW.md.

not rated 55 5mo ago A 61 tokens

code-scanner

250

solygambas/python-openai-projects

Agent Claude Code

Use this agent when you need to audit a Next.js codebase for security vulnerabilities, performance bottlenecks, code quality issues, or opportunities to refactor code into smaller components. This agent focuses on actual implemented code and does not flag missing features or unimplemented…

not rated 55 5mo ago A 383 tokens

navikt/copilot

Agent

Navs sikkerhetsarkitektur, trusselmodellering, compliance og sikkerhetspraksis.

not rated 54 changed today A 25 tokens original MIT

scope-audit

252

tayontech/SCOPE

Agent

SCOPE audit orchestrator — single entry point for the full audit pipeline. Runs Python SCOPE runtime enumeration, chains attack-path reasoning, verification, defensive controls, post-processing, and dashboard generation. Invoke with /scope:audit .

not rated 54 2mo ago A 52 tokens original MIT

scope-investigate

253

tayontech/SCOPE

Agent

SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — step-by-step guided queries, investigation timelines, and IOC correlation. Invoke with /scope:investigate.

not rated 54 2mo ago A 42 tokens original MIT

auth-expert

255

Daliagents-com/agentsge-1

Agent

Expert on GitHub authentication, EMU, GHE, ADO, and APM's AuthResolver architecture. Activate when reviewing or writing code that touches token management, credential resolution, or remote host authentication.

not rated 53 +1 1mo ago A 46 tokens

flutter-architect

256

cleydson/flutter-claude-code

Agent Claude Code

Use this agent when designing Flutter application architecture, project structure, and design patterns. Specializes in Clean Architecture, feature organization, dependency injection, navigation, and scalable code organization. Examples: Context: User starting new Flutter project user: 'I need to set up a new…

not rated 52 6mo ago A 0 tokens

security-reviewer

257

weny911/AI-coding-almighty

Agent Claude Code

Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.

not rated 51 6mo ago A 52 tokens

security-audit

258

Automattic/wordpress-atmosphere

Agent Claude Code

Defensive first-party security review of the plugin's own code to detect and help fix weaknesses (SSRF, OAuth bypass, XSS, token leakage, DPoP issues) before release. Use when asked to check security, harden the plugin, or review the code for vulnerabilities to fix.

not rated 51 today C 64 tokens

spec-check

259

Automattic/wordpress-atmosphere

Agent Claude Code

Check AT Protocol and standard.site spec compliance. Use when asked to verify Lexicon conformance, OAuth flow correctness, or record schema validation.

not rated 51 today A 31 tokens

infrastructure-agent

260

CDSecurity/cdsecurity-skills

Agent

You have: framework, projectdir, and Bash/Read/Glob/Grep tools. Do NOT read source .sol files. Check project infrastructure only.

not rated 52 +1 4mo ago A 0 tokens original MIT

sageox/ox

Agent Claude Code

BYOK (Bring-Your-Own-Key) and OAuth token security expert. Deep on cross-platform OS keychain integration (macOS Keychain, Linux Secret Service / kwallet / gnome-keyring, Windows Credential Manager), token caching tradeoffs, env-var hygiene, accidental-commit prevention beyond gitleaks, sub-process credential leakage…

not rated 51 today A 190 tokens original MIT

supply-chain-analyst

262

sageox/ox

Agent Claude Code

Software supply-chain security expert. Deep on Socket.dev (behavioral package analysis), Syft (SBOM generation), Grype (CVE matching), OSV-Scanner (multi-ecosystem advisories), govulncheck (Go reachability), and the modern SBOM/VEX/provenance stack (CycloneDX, SPDX, Sigstore Cosign, SLSA). Use PROACTIVELY when…

not rated 51 today A 166 tokens original MIT

python-security

263

sebastienrousseau/pain001

Agent

Security Maintainer operating under PySentinel Zero-Trust Model. Enforces OWASP principles, CVE prevention, supply chain integrity, XXE/XSD validation, and secure development practices with advanced production tollgates.

not rated 49 3d ago A 47 tokens original Apache-2.0

qa-reviewer

264

seungmanchoi/react-native-fsd-agent-template

Agent Claude Code

A code-review and quality-checking agent for projects that use Feature-Sliced Design. It checks architecture rules, type safety, and security, and can run type checks and linting.

not rated 50 1mo ago A 88 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: