Security agents

4,196 tagged Security, measured the same way as everything else here.

Browse within: ai-security 90cybersecurity 77Autonomous Agents 74bug-bounty 73ai-security-tool 64appsec 63agentic-coding 57Multi-Agent 51offensive-security 51multi-agent-systems 50ctf 47claude-code-skills 44compliance 40agentic 39

Smart Exclude

145

agentgg-dev/agentgg

Agent

Picks folders a SAST run doesn't need to scan (test directories, fixtures, docs, generated code, vendored deps) so the scan skips them.

194 5d ago A 36 tokens original Apache-2.0

Project Recon

146

agentgg-dev/agentgg

Agent

Fast, high-level survey that orients the security agents — what the project is, its stack, auth model, integrations, and notable areas.

194 5d ago A 32 tokens original Apache-2.0

erans/lunaroute

Agent Claude Code

Use this agent when you need expert review of Rust code, particularly web services, HTTP implementations, or security-critical systems. Trigger this agent after completing logical code units like implementing HTTP handlers, API endpoints, authentication systems, middleware, database operations, or any Rust web…

187 1mo ago A 323 tokens original Apache-2.0

code-reviewer

148

kid-sid/claude-spellbook

Agent Claude Code

Use this agent to perform a thorough two-stage review of a pull request or set of changed files — first verifying spec compliance, then evaluating code quality, security, test coverage, and performance. Prefer this over the inline /review command when the diff spans more than 5 files or more than 300 lines.

187 28d ago A 66 tokens original MIT

qa-code-auditor

149

ayoubben18/ab-method

Agent Claude Code

Use this agent when you need comprehensive code quality assessment and improvement recommendations across a codebase or significant code sections. Examples: Context: User has completed a major feature implementation and wants to ensure code quality before merging. user: 'I've finished implementing the user…

187 1mo ago A 237 tokens original MIT

idor-agent

150

BugTraceAI/BugTraceAI-CLI

Agent

The IDOR Agent (Insecure Direct Object Reference) is a specialist agent in BugTraceAI that detects and exploits IDOR vulnerabilities. It uses a WET→DRY two-phase pipeline with LLM-powered deduplication and optional deep exploitation analysis.

183 +3 4d ago A 0 tokens AGPL-3.0

security-reviewer

151

autohandai/code-cli

Agent

Review concrete security boundaries with evidence and exploitability context.

181 7d ago A 10 tokens original Apache-2.0

code-reviewer

154

echoVic/blade-code

Agent Claude Code

Expert code review specialist. Proactively reviews code for quality, security, and maintainability. Use immediately after writing or modifying code.

177 3d ago A 30 tokens original MIT

gdpr-specialist

156

fmflurry/settings-opencode

Agent Claude Code

MUST delegate for GDPR/privacy/data-protection compliance review of code (frontend, backend, database, infrastructure layers, full stack). FRANCE/CNIL-focused: audits against French GDPR rules, CNIL recommendations, Loi Informatique et Libertés. Covers consent flows, cookies/trackers, PII handling, data-subject…

171 +1 21d ago A 124 tokens original MIT

code-reviewer

157

romiluz13/cc10x

Agent

Part of cc10x

Adversarial multi-dimensional code review — security, performance, correctness, spec compliance, maintainability. Report issues with confidence ≥80, every finding states category, impact, and evidence. Runs after component-builder in BUILD workflows.

164 1mo ago A 49 tokens original MIT

sec-auditor

158

iii-experimental/agentos

Agent

Part of agentos

Security audit agent — scans for vulnerabilities, checks permissions, reviews secrets.

162 3mo ago A 18 tokens original Apache-2.0

attribution

159

DataDog/pathfinding.cloud

Agent Claude Code ✓ vendor

Find references to this attack path to include in the yaml and try to find the person who identified this attack path.

152 8d ago A 26 tokens original Apache-2.0

api-auth-analyzer

162

25smoking/Gwxapkg

Agent

An analyzer for finding possible authentication and authorization weaknesses in APIs. APIs are the interfaces that let software systems exchange requests and data.

151 +3 13d ago A 0 tokens original MIT

burp-correlator

163

25smoking/Gwxapkg

Agent

A tool for matching a raw Burp Suite HTTP request with the corresponding Gwxapkg source API, pseudocode, and call chain. Burp Suite is a web-security tool that records and edits HTTP requests.

151 +3 13d ago A 0 tokens original MIT

25smoking/Gwxapkg

Agent

A business-risk analyst that examines application workflows such as sign-in, verification codes, password resets, licence searches, orders, and payments.

151 +3 13d ago A 0 tokens original MIT

Fausto-404/ai-mobile-reverse-skills

Agent

A mobile-app reverse-engineering analysis role that links captured requests, request fields, signatures, authentication data, and code locations. Reverse engineering here means examining local app code and traffic to understand how they correspond.

150 +1 19d ago A 0 tokens original MIT

Fausto-404/ai-mobile-reverse-skills

Agent

A mobile reverse-engineering agent for analyzing native cryptography code, JNI bridges, and shared-library logic. JNI is the interface that lets Java or Kotlin code call native code, while a shared library is compiled code such as an Android .so file.

150 +1 19d ago A 0 tokens original MIT

acx-reviewer

168

KbWen/agentic-os

Agent Claude Code

AgentCortex /review phase executor. Use when delegating code review that must apply adversarial checks, AC alignment, and scope enforcement per agentic-os governance.

149 9d ago A 38 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: