Security agents

3,300 tagged Security, measured the same way as everything else here.

Browse within: claude-code-plugin 192ai-security 115cybersecurity 101ai-coding 93bug-bounty 78Autonomous Agents 73ai-security-tool 70Multi-Agent 65agentic-coding 61claude-code-skills 58appsec 57ctf 50offensive-security 50multi-agent-systems 47

AGENT_REGISTRY

265

IRsoctierDT/IANUA-Broker

Agent

This registry provides a single portfolio-facing inventory of agents for MCP Sentinel — Agent Trust Broker. Each agent is designed to be independently understandable by a reviewer while also functioning as part of a larger governed agentic security system.

not rated 2 11d ago A 0 tokens original Apache-2.0

hunter

266

kleosr/kleosrules

Agent

Bugbot-class logic-bug and vulnerability hunter for the current diff. Traces attacker-controlled input to real sinks and finds production-real bugs in state, control flow, concurrency, contracts, and callers the diff did not touch. Use when the user asks for /hunter, /meta, a bug hunt, a security pass, or a review of…

not rated 2 4d ago A 95 tokens original MIT

corp

267

jmfloreszazo/agent-eval-poc

Agent

Corp governance gateway. Single entry point: instruments telemetry, opens the parent case span, runs scenario-3/src/corp.py and delegates the analysis to @fraud-analyst and @legal-counsel. Never answers the case itself. USE WHEN: governed fraud + legal analysis, telemetry-instrumented case run, corp telemetry, run…

not rated 2 2mo ago A 75 tokens original MIT

task-validator

268

stepanenkoviktor0110-boop/ai-dev-methodology

Agent

Validates task files against task template and task-creator rules. Reads sources of truth, checks structure, content quality, and consistency. Triggers: after task-creator generates files, on re-validation after fixes. Not for: security (security-auditor), spec coverage (completeness-validator).

not rated 2 10d ago A 63 tokens

layer-leak-auditor

269

sublimecoder/aios

Agent Claude Code

Read-only auditor that checks a note, file, or diff for cross-scope leaks before publishing, sharing, or committing. Only applicable when the OPTIONAL wall is enabled — i.e. some scope in AIOS/Systems/layers.tsv declares identifying tokens. Use before any external-facing action (publish, post, send, apply) or when…

not rated 2 1mo ago A 88 tokens original MIT

code-reviewer

270

acegalaxy-co/ace_commons-ccswitch-cli

Agent Claude Code

Review code changes (staged diff, branch range, or specific files) for correctness, security, style consistency, and rule compliance. Use before large commits or before deploying to prod. Returns issue list + severity.

not rated 2 18d ago A 47 tokens

chaos-dancer

271

theshadow27/mcp-cli

Agent Claude Code

Use this agent to predict how users will creatively misuse and weaponize features for social manipulation, fraud, or unintended behavioral cascades. This agent understands that every feature becomes a tool for gaming the system and unintended consequences.

not rated 2 5d ago A 48 tokens original MIT

security-reviewer

272

johnlanda/agentic-coding-starter-kit

Agent Claude Code

Reviews code changes for security vulnerabilities, credential leaks, and injection risks. Use when modifying authentication, authorization, data handling, or API endpoints.

not rated 2 4mo ago A 32 tokens

r0r1/claude_code_config

Agent

Use this agent when you need expert code review for Ruby on Rails or Next.js applications, focusing on best practices, DRY principles, Clean Code standards, security vulnerabilities, database optimization, and Test-Driven Development. This agent should be invoked after writing or modifying code to ensure it meets…

not rated 2 9mo ago A 0 tokens

adversarial-auditor

274

xcodethink/open-claude-code-skills

Agent

A read-only quality-audit agent that treats “finished” as something to test rather than assume. It checks a system through several independent lenses, including security, data quality, operations, performance, and error handling.

not rated 2 29d ago A 128 tokens original MIT

security-auditor

275

orlando-japan/claude-code-setting

Agent

Security-focused code review. Use when the user asks to "audit for security", "check for vulnerabilities", review auth/authz/crypto/input handling code, or before shipping anything that touches secrets, user input, or external services. Also use proactively when reviewing dependency additions.

not rated 2 3mo ago A 59 tokens original MIT

vba_code_reviewer

276

RenRMT/claude-code-vba-skills

Agent

Senior VBA code review specialist. Use after writing or modifying VBA to review for security, quality, performance, and best practices before committing or releasing.

not rated 2 5mo ago A 35 tokens original MIT

typescript-reviewer

277

Cyvid7-Darus10/claude-code-config

Agent

Expert TypeScript/JavaScript code reviewer specializing in type safety, async correctness, Node/web security, and idiomatic patterns. Use for all TypeScript and JavaScript code changes. MUST BE USED for TypeScript/JavaScript projects.

not rated 2 2mo ago A 51 tokens copy · 95% MIT

jessefmoore/offensive-claude-code

Agent

Alternate pentest report renderer in "operator casebook" style — a single self-contained HTML deliverable with phosphor-green CRT aesthetic, dossier hero, executive briefing, master timeline, attack graph, per-act chapters, host grid, TTP matrix, attack chains, dead-ends, and close stamp. Coexists with the markdown…

not rated 2 3mo ago A 94 tokens original MIT

security-reviewer

279

anshajk/claude-security

Agent Claude Code

Independent OWASP security reviewer. Invoke (proactively or on request) to run a security-only pass over a diff, endpoint, or file before it merges. Reports vulnerabilities with file:line, exploit, and fix; never modifies code.

not rated 2 1mo ago A 52 tokens

security-engineer

280

askwigconsulting/cohort

Agent

Threat modeling, secure-by-default review, secret hygiene, and security audits of specific changes. Use for a security-focused pass on a diff, file, or design.

not rated 2 27d ago A 37 tokens original MIT

security-engineer

282

NickPolyder/NP.CoPilot.Config

Agent

Senior Security Engineer specialized in threat modeling, vulnerability analysis, authentication/authorization patterns, secure coding practices, and ensuring application and infrastructure security across the full stack.

not rated 2 9d ago A 35 tokens original MIT

code-reviewer

283

vanessamarely/ai-playbook-reposito

Agent Claude Code

Senior code reviewer that evaluates changes across five dimensions — correctness, readability, architecture, security, and performance. Use for thorough code review before merge.

not rated 2 1mo ago A 33 tokens original MIT

security-specialist

285

norlanp/dotfiles

Agent Codex

OWASP-aware security specialist for vulnerability assessment, threat modeling, and secure architecture.

not rated 2 9d ago A 19 tokens

code-reviewer

286

theogravity/bun-elysiajs-starter-turbo-monorepo

Agent Claude Code

Expert code reviewer specializing in code quality, security vulnerabilities, and best practices across multiple languages. Masters static analysis, design patterns, and performance optimization with focus on maintainability and technical debt reduction.

not rated 2 7d ago A 42 tokens original MIT

Code Review (Codex)

287

pierceboggan/prompt-lsp

Agent

Code review following VS Code contribution standards — correctness, lifecycle, naming, layering, accessibility, and security.

not rated 2 6mo ago A 26 tokens

code-reviewer

288

AbdulmalekAlshugaa/claude-agents-fullstack

Agent

Use after implementing a change and before committing/PR. Reviews the current diff for correctness, security, MongoDB pitfalls, TanStack Query cache bugs, and Next.js mistakes. Read-only; returns findings ranked by severity.

not rated 3 yesterday A 48 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: