sec-auditor
169Agent
Part of agentos
Security audit agent — scans for vulnerabilities, checks permissions, reviews secrets.
4,251 tagged Security, measured the same way as everything else here.
Browse within: Autonomous Agents 74ai-security-tool 64appsec 63ai-security 62agentic-coding 59Multi-Agent 51offensive-security 51multi-agent-systems 50cybersecurity 49claude-code-skills 47bug-bounty 45compliance 40agent-orchestration 38agentic 36
Agent
Part of agentos
Security audit agent — scans for vulnerabilities, checks permissions, reviews secrets.
Agent Claude Code ✓ vendor
Find references to this attack path to include in the yaml and try to find the person who identified this attack path.
Agent Claude Code ✓ vendor
Research and add detection tool coverage to attack paths.
Agent Claude Code ✓ vendor
Research and add learning environment information to attack paths.
Agent
An analyzer for finding possible authentication and authorization weaknesses in APIs. APIs are the interfaces that let software systems exchange requests and data.
Agent
A tool for matching a raw Burp Suite HTTP request with the corresponding Gwxapkg source API, pseudocode, and call chain. Burp Suite is a web-security tool that records and edits HTTP requests.
Agent
A business-risk analyst that examines application workflows such as sign-in, verification codes, password resets, licence searches, orders, and payments.
Fausto-404/ai-mobile-reverse-skills
Agent
A mobile-app reverse-engineering analysis role that links captured requests, request fields, signatures, authentication data, and code locations. Reverse engineering here means examining local app code and traffic to understand how they correspond.
Fausto-404/ai-mobile-reverse-skills
Agent
A mobile reverse-engineering agent for analyzing native cryptography code, JNI bridges, and shared-library logic. JNI is the interface that lets Java or Kotlin code call native code, while a shared library is compiled code such as an Android .so file.
Fausto-404/ai-mobile-reverse-skills
Agent
A security-analysis agent that checks code for weak encryption and other high-risk vulnerabilities, then records how much evidence supports each finding.
Agent Claude Code
AgentCortex /review phase executor. Use when delegating code review that must apply adversarial checks, AC alignment, and scope enforcement per agentic-os governance.
webdevtodayjason/context-forge
Agent
You scan {{#if projectName}}{{projectName}}{{else}}the project{{/if}} for security issues across three axes: application code (OWASP Top 10), dependencies (CVEs), and credential leaks. You are conservative — prefer false positives over false negatives, but always tag confidence.
Agent
Part of kk
Independent code reviewer with no authorship attachment. Reviews git diffs for SOLID violations, security risks, code quality issues, and architecture smells using the SOLID code review methodology.
Agent
Part of claude-code-agents
Comprehensive security analysis. OWASP Top 10, injection, auth, secrets, headers.
Agent
🛡️ Security engineer focused on vulnerability detection, threat modeling, and secure coding practices. Saves audit reports to docs/security-audits/ and creates GitHub issues for each finding.
Agent
Code review specialist for quality and security analysis.
LF-Decentralized-Trust-labs/gitmesh
Agent Gemini CLI
GitMesh: Policy-as-Code Engine for Open Source AI Agent Orchestration.
LF-Decentralized-Trust-labs/gitmesh
Agent
GitMesh: Policy-as-Code Engine for Open Source AI Agent Orchestration.
LF-Decentralized-Trust-labs/gitmesh
Agent
GitMesh: Policy-as-Code Engine for Open Source AI Agent Orchestration.
Agent
Code review specialist for quality and security analysis.
Agent
Part of Claude-AD
Reasons about low-privilege-to-Domain-Admin paths in an authorized Active Directory assessment. Takes the enumerator's inventory plus the BloodHound CE graph and works out which edges to chain (GenericAll to ResetPassword to a privileged group, Kerberoast to crack to privilege, ADCS ESC1/ESC8, DCSync). It plans and…
Agent
Part of Claude-AD
Runs the COLLECTION phase of an authorized Active Directory assessment from a low-privilege domain account. Orchestrates standard tools (netexec/nxc, impacket, rusthound-ce or bloodhound-python, certipy) to enumerate users, groups, SPNs, interesting ACLs, ADCS templates and trusts, then returns a structured inventory…
Agent
Part of Claude-AD
Executes ONE exploitation step from an approved attack plan in an authorized Active Directory assessment, invoking the matching technique skill (kerberos-attacks, adcs-attacks, acl-abuse, coercion-ntlm-relay) with the standard tool. Always asks for human confirmation before any action that modifies the directory…
Agent
Part of bitwarden-security-engineer
Application security engineer specializing in vulnerability triage, threat modeling, and secure code analysis. Use for security findings remediation, threat model generation, dependency audits, and architecture security review.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: