Smart Exclude
145Agent
Picks folders a SAST run doesn't need to scan (test directories, fixtures, docs, generated code, vendored deps) so the scan skips them.
4,196 tagged Security, measured the same way as everything else here.
Browse within: ai-security 90cybersecurity 77Autonomous Agents 74bug-bounty 73ai-security-tool 64appsec 63agentic-coding 57Multi-Agent 51offensive-security 51multi-agent-systems 50ctf 47claude-code-skills 44compliance 40agentic 39
Agent
Picks folders a SAST run doesn't need to scan (test directories, fixtures, docs, generated code, vendored deps) so the scan skips them.
Agent
Fast, high-level survey that orients the security agents — what the project is, its stack, auth model, integrations, and notable areas.
Agent Claude Code
Use this agent when you need expert review of Rust code, particularly web services, HTTP implementations, or security-critical systems. Trigger this agent after completing logical code units like implementing HTTP handlers, API endpoints, authentication systems, middleware, database operations, or any Rust web…
Agent Claude Code
Use this agent to perform a thorough two-stage review of a pull request or set of changed files — first verifying spec compliance, then evaluating code quality, security, test coverage, and performance. Prefer this over the inline /review command when the diff spans more than 5 files or more than 300 lines.
Agent Claude Code
Use this agent when you need comprehensive code quality assessment and improvement recommendations across a codebase or significant code sections. Examples: Context: User has completed a major feature implementation and wants to ensure code quality before merging. user: 'I've finished implementing the user…
Agent
The IDOR Agent (Insecure Direct Object Reference) is a specialist agent in BugTraceAI that detects and exploits IDOR vulnerabilities. It uses a WET→DRY two-phase pipeline with LLM-powered deduplication and optional deep exploitation analysis.
Agent
Review concrete security boundaries with evidence and exploitability context.
Agent Claude Code
Attempts to break implementations.
Agent Claude Code
Security analysis using narsil-mcp.
Agent Claude Code
Expert code review specialist. Proactively reviews code for quality, security, and maintainability. Use immediately after writing or modifying code.
jmckinley/claude-code-resources
Agent
Performs security audits and vulnerability checks.
Agent Claude Code
MUST delegate for GDPR/privacy/data-protection compliance review of code (frontend, backend, database, infrastructure layers, full stack). FRANCE/CNIL-focused: audits against French GDPR rules, CNIL recommendations, Loi Informatique et Libertés. Covers consent flows, cookies/trackers, PII handling, data-subject…
Agent
Part of cc10x
Adversarial multi-dimensional code review — security, performance, correctness, spec compliance, maintainability. Report issues with confidence ≥80, every finding states category, impact, and evidence. Runs after component-builder in BUILD workflows.
Agent
Part of agentos
Security audit agent — scans for vulnerabilities, checks permissions, reviews secrets.
Agent Claude Code ✓ vendor
Find references to this attack path to include in the yaml and try to find the person who identified this attack path.
Agent Claude Code ✓ vendor
Research and add detection tool coverage to attack paths.
Agent Claude Code ✓ vendor
Research and add learning environment information to attack paths.
Agent
An analyzer for finding possible authentication and authorization weaknesses in APIs. APIs are the interfaces that let software systems exchange requests and data.
Agent
A tool for matching a raw Burp Suite HTTP request with the corresponding Gwxapkg source API, pseudocode, and call chain. Burp Suite is a web-security tool that records and edits HTTP requests.
Agent
A business-risk analyst that examines application workflows such as sign-in, verification codes, password resets, licence searches, orders, and payments.
Fausto-404/ai-mobile-reverse-skills
Agent
A mobile-app reverse-engineering analysis role that links captured requests, request fields, signatures, authentication data, and code locations. Reverse engineering here means examining local app code and traffic to understand how they correspond.
Fausto-404/ai-mobile-reverse-skills
Agent
A mobile reverse-engineering agent for analyzing native cryptography code, JNI bridges, and shared-library logic. JNI is the interface that lets Java or Kotlin code call native code, while a shared library is compiled code such as an Android .so file.
Fausto-404/ai-mobile-reverse-skills
Agent
A security-analysis agent that checks code for weak encryption and other high-risk vulnerabilities, then records how much evidence supports each finding.
Agent Claude Code
AgentCortex /review phase executor. Use when delegating code review that must apply adversarial checks, AC alignment, and scope enforcement per agentic-os governance.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: