Agent Claude Code
Round 1 verification — re-runs PoCs with maximum skepticism, checks severity inflation, filters non-bugs.
3,479 tagged Security, measured the same way as everything else here.
Browse within: claude-code-plugin 192ai-coding 112Autonomous Agents 76ai-security-tool 64appsec 63ai-security 54multi-agent-systems 51offensive-security 51agentic-coding 49cybersecurity 47agentic 44agent-orchestration 41compliance 40bug-bounty 38
Agent Claude Code
Round 1 verification — re-runs PoCs with maximum skepticism, checks severity inflation, filters non-bugs.
Agent Claude Code
Collects bounded pre-grade evidence packs for final reportable findings (HTTP via bobhttpscan; SC via family runners).
Agent
QC sub-agent. Executes tests, static analysis, and security tools. Asks user for permission before installing missing dependencies.
Agent Claude Code
Subagent that reviews PR diffs for security, authentication, and authorization. Launched by the review-pr command.
Agent
Finds flaws, security vulnerabilities, edge cases, and logical errors. Assumes the code is broken.
mturac/everything-openai-codex
Agent
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.
Agent Claude Code
Scan the target codebase for vulnerabilities in a single category. Use grep patterns to find candidates, read code to confirm in context, eliminate false positives, and produce evidence-grounded findings.
Jamkris/everything-gemini-code
Agent
Expert code review specialist. Proactively reviews code for quality, security, and maintainability. Use immediately after writing or modifying code. MUST BE USED for all code changes.
Jamkris/everything-gemini-code
Agent
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.
Agent Claude Code
Use this agent when you need comprehensive code review and quality assessment. This includes: after implementing new features or refactoring existing code, before merging pull requests or deploying to production, when investigating code quality issues or technical debt, when you need security vulnerability assessment…
stefan-jansen/claude-code-toolkit
Agent
Validates risk controls, position sizing, and production safety mechanisms for deployment readiness.
Agent
Code review specialist for quality and security analysis.
ilyasibrahim/claude-agents-coordination
Agent
Security scanning, vulnerability assessment, threat modeling, and compliance review. Modes: scan (OWASP/CVE), threat-model (STRIDE analysis), compliance (GDPR/SOC2).
Agent Claude Code
Use this agent when designing API routes, database schemas, implementing geocoding logic, or solving reliability/security/performance issues in StarMapper's server-side code. Examples: adding a new API route, modifying Prisma schema, debugging geocoding cascade, optimizing the chunk endpoint.
Agent Claude Code
Apply security patches from security-auditor findings. Requires audit report as input. Always proposes patches for human review — never applies without approval.
hamzafarooq/multi-agent-course
Agent Claude Code
Scan code changes and flag security issues, logic errors, and missing tests. Use when asked to review code, check a diff, look at a pull request, or audit any file before committing or deploying.
Agent Claude Code
Active Directory and Windows domain attack specialist. Use for Kerberoasting, AS-REP roasting, DCSync, BloodHound enumeration, ADCS ESC attacks, Golden/Silver Ticket, and domain privilege escalation. Triggers on: kerberoast, AS-REP, bloodhound, DCSync, golden ticket, ADCS, ESC, domain controller, LDAP, GPO, AD, domain…
Agent Claude Code
API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignment, authentication bypass, rate limit evasion, JWT attacks, GraphQL introspection abuse, API enumeration, and OWASP API Top 10. Triggers on: API, REST, GraphQL, gRPC, WebSocket, BOLA, IDOR, mass assignment, API…
Agent Claude Code
Password cracking and credential attack specialist. Use when working with password hashes, hash cracking, wordlist attacks, credential analysis, or password auditing. Triggers on: password, hash, crack, hashcat, john, wordlist, NetNTLMv2, Kerberoast, NTLM, bcrypt, credential, ASREP, JWT crack, mask attack, rule…
Agent
GitHub Actions specialist focused on secure CI/CD workflows, action pinning, OIDC authentication, permissions least privilege, and supply-chain security.
Agent Claude Code
Static code review for security, performance, and quality. Read-only — no commands. Run before done-gate to catch issues before committing.
microsoftgbb/agentic-platform-engineering
Agent
An expert Kubernetes administrator agent specializing in cluster troubleshooting, networking, NetworkPolicy, security posture, admission controllers, and GitOps workflows. The agent assesses initial reports, independently verifies or rejects claims, triages root causes, and proposes or applies fixes (including GitOps…
Agent Claude Code
Use before any PR or release to audit security. Checks for path traversal, stdout pollution, credential leaks, and unsafe subprocess execution.
SamarthaKV29/antigravity-god-mode
Agent
Multi-agent coordination and task orchestration. Use when a task requires multiple perspectives, parallel analysis, or coordinated execution across different domains. Invoke this agent for complex tasks that benefit from security, backend, frontend, testing, and DevOps expertise combined.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: