Security agents

3,129 tagged Security, measured the same way as everything else here.

Browse within: claude-code-plugin 191ai-security 114cybersecurity 99ai-coding 89bug-bounty 78Autonomous Agents 77ai-security-tool 70Multi-Agent 62agentic-coding 59claude-code-skills 59skills 58appsec 55offensive-security 51ctf 50

kidboy-man/vibe-engineering

Agent Claude Code

Security and data-safety review for backend/API/database changes, especially authz, tenant isolation, tokens/codes, billing, RLS, secrets, and unsafe logs.

not rated 2 1mo ago A 39 tokens

php-reviewer

314

Effulgent-Point/paw

Agent Claude Code

PHP/Laravel-specific reviewer — SQL injection, mass assignment, CSRF, N+1 Eloquent, auth middleware, type safety, queue idempotency.

not rated 2 26d ago A 37 tokens original MIT

cmmc-assessor

315

vaquarkhan/compliance-agent-skills

Agent Claude Code

Simulates a CMMC Level 2 assessment perspective for organizations handling Controlled Unclassified Information (CUI) — not a C3PAO certification or SPRS submission.

not rated 2 12d ago A 0 tokens original MIT

security-auditor

316

hwchany0ung/claude-agent-playbook

Agent Claude Code

Use for OWASP Top 10 security audits, JWT/auth flow review, database RLS policy validation, API rate limiting checks, and vulnerability assessment. Read-only analysis agent — does NOT modify code. Use after major feature implementation or before production releases.

not rated 2 3mo ago A 55 tokens

security-auditor

317

vignesh2027/AI-AGENT-SKILLS

Agent Claude Code

You are a Security Engineer conducting a security review. You apply adversarial thinking: assume malicious users, assume compromised dependencies, assume insider threats. Your goal is to find exploitable vulnerabilities, not just to find "bad practices.".

not rated 2 7d ago A 4 tokens original MIT

VoidTechnology/voidtech-claude-plugins

Agent Claude Code

A security-review agent for Voidtech Loop, a tool that runs commands and manages Git workspaces. It performs a read-only, adversarial review and reports only reproducible critical or high-severity problems.

not rated 2 1mo ago A 48 tokens original Apache-2.0

parser-generator

319

Huleinpylo/kali-agents-mcp

Agent Claude Code

Use this agent to generate parsers for security tool outputs. Examples include:\n\n \nContext: Developer is integrating a new security tool into an MCP server.\nuser: "I need to parse nmap XML output to extract open ports and services."\nassistant: "I'll use the parser-generator agent to create a robust nmap XML…

not rated 2 5d ago A 0 tokens GPL-3.0

ios-runtime

320

xtofuub/frida-mcp-server

Agent Claude Code

Hunts client-side logic flaws in an attached iOS app — enumerates ObjC/Swift gate methods, traces them on real flows (human drives the UI), flips boolean returns, and verifies whether capability is actually gained. Use for the logic/runtime phase.

not rated 2 +1 2mo ago A 55 tokens original MIT

code-reviewer

321

pixeleishen/wind-mcp-server

Agent Claude Code

Reviews code changes in this project for correctness, security, and adherence to project conventions. Use after writing or modifying TypeScript or Python files. Checks for known anti-patterns specific to this codebase.

not rated 2 6mo ago A 44 tokens

birre-mcp

322

boecht/birre

Agent Claude Code

BiRRe QA mode for tool validation and demonstration.

not rated 2 6d ago A 15 tokens original Unlicense

c-pro-reviewer

324

docevilOck/agent-skills-hook

Agent Claude Code

A code-review agent for C projects that checks coding standards, quality, security, architecture, performance, and unused or repeated code.

not rated 2 2d ago A 80 tokens

security-reviewer

325

wardawgmalvicious/agent-config

Agent Claude Code

Security scan specialist. Use proactively before commits, during code reviews, or when asked to audit security. Scans for hardcoded credentials, secrets, injection risks, unsafe deserialization, overly permissive config, and risky Azure/cloud patterns. Returns findings with severity and file:line refs; does not modify…

not rated 1 +1 changed 2d ago A 66 tokens original MIT

code-reviewer

326

Sequentum/sequentum-mcp

Agent Claude Code

Use this agent when you need to conduct comprehensive code reviews focusing on code quality, security vulnerabilities, and best practices. Specifically:\n\n \nContext: Developer has submitted a pull request with changes to critical authentication logic in a TypeScript backend service.\nuser: "Can you review this PR…

not rated 1 2d ago A 521 tokens original MIT

_index

327

stevologic/security-recipes.ai

Agent Claude Code

Compare Codex, Claude Code, Cursor, Copilot, Devin, Shiba Studio, Hermes, and OpenClaw for AI vulnerability remediation with bounded instructions and review gates.

not rated 1 yesterday A 35 tokens original Apache-2.0

data-integrity

330

vindm/dotclaude

Agent Claude Code

Database integrity auditor — queries the persistent store for incomplete enrichment, orphaned references, stuck state-machine rows, cross-tenant leaks, and invariant violations. Read-only; produces a Good/Gaps/Critical health report with example IDs, diagnostic hypotheses, and severity tiers. Run after pipeline…

not rated 1 2d ago A 74 tokens original MIT

ReviewToolkits/cpython-security-toolkit

Agent Claude Code

Analyzes CPython security fix commits and checks whether the fix was applied to all code paths through the same invariant. The most important agent for preventing second-round CVEs. Invoke after identifying a security fix commit or when reviewing recent type-security labeled changes.

not rated 1 6d ago A 57 tokens

vapt-auth-tester

333

bhuvangupta/vapt-claude

Agent Claude Code

You are an authentication and access control testing specialist. You are one of 3 parallel agents in Wave 3 of the VAPT audit.

not rated 1 5mo ago A 0 tokens original MIT

autopilot

334

guib1/red-team-docker

Agent Claude Code

Autonomous hunt loop agent. Runs the full hunt cycle (scope → recon → rank → hunt → validate → report) without stopping for approval at each step. Configurable checkpoints (--paranoid, --normal, --yolo). Uses scopechecker.py for deterministic scope safety on every outbound request. Logs all requests to audit.jsonl.…

not rated 1 5mo ago A 84 tokens

code-reviewer

335

msopariw/GitHubCopilotDemo

Agent Claude Code

Code reviewer agent that checks code quality, security, and best practices for the Todo app.

not rated 1 1mo ago A 17 tokens

Reviewer

336

zexion7873/copilot-setting

Agent Claude Code

Perform code reviews, security audits (OWASP Top 10), SQL and schema migration reviews, and Maven pom.xml dependency checks (within code review). Each review mode follows its own checklist and severity model.

not rated 1 1mo ago A 43 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: