Security agents

3,479 tagged Security, measured the same way as everything else here.

Browse within: claude-code-plugin 192ai-coding 112Autonomous Agents 76ai-security-tool 64appsec 63ai-security 54multi-agent-systems 51offensive-security 51agentic-coding 49cybersecurity 47agentic 44agent-orchestration 41compliance 40bug-bounty 38

brutalist-verifier

193

vmihalis/hacker-bob

Agent Claude Code

Round 1 verification — re-runs PoCs with maximum skepticism, checks severity inflation, filters non-bugs.

not rated 97 5d ago A 28 tokens original Apache-2.0

evidence-agent

194

vmihalis/hacker-bob

Agent Claude Code

Collects bounded pre-grade evidence packs for final reportable findings (HTTP via bobhttpscan; SC via family runners).

not rated 97 5d ago A 28 tokens original Apache-2.0

QCAuditor

195

attilaszasz/sdd-pilot

Agent

QC sub-agent. Executes tests, static analysis, and security tools. Asks user for permission before installing missing dependencies.

not rated 95 today A 29 tokens original MIT

adversarial-reviewer

197

pascalorg/skills

Agent

Finds flaws, security vulnerabilities, edge cases, and logical errors. Assumes the code is broken.

not rated 90 5mo ago A 21 tokens

security-reviewer

198

mturac/everything-openai-codex

Agent

Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.

not rated 90 10d ago A 52 tokens original MIT

category-scanner

199

bluzir/claude-pipe

Agent Claude Code

Scan the target codebase for vulnerabilities in a single category. Use grep patterns to find candidates, read code to confirm in context, eliminate false positives, and produce evidence-grounded findings.

not rated 89 6mo ago A 3 tokens original MIT

code-reviewer

200

Jamkris/everything-gemini-code

Agent

Expert code review specialist. Proactively reviews code for quality, security, and maintainability. Use immediately after writing or modifying code. MUST BE USED for all code changes.

not rated 87 3mo ago A 38 tokens original MIT

security-reviewer

201

Jamkris/everything-gemini-code

Agent

Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injection, unsafe crypto, and OWASP Top 10 vulnerabilities.

not rated 87 3mo ago A 52 tokens original MIT

code-reviewer

202

duongthinh03/portfolio

Agent Claude Code

Use this agent when you need comprehensive code review and quality assessment. This includes: after implementing new features or refactoring existing code, before merging pull requests or deploying to production, when investigating code quality issues or technical debt, when you need security vulnerability assessment…

not rated 85 2mo ago A 0 tokens

reviewer

204

joelhooks/pi-tools

Agent

Code review specialist for quality and security analysis.

not rated 84 7d ago A 11 tokens

security-engineer

205

ilyasibrahim/claude-agents-coordination

Agent

Security scanning, vulnerability assessment, threat modeling, and compliance review. Modes: scan (OWASP/CVE), threat-model (STRIDE analysis), compliance (GDPR/SOC2).

not rated 83 3mo ago A 41 tokens original Unlicense

backend-architect

206

FlorianBruniaux/starmapper

Agent Claude Code

Use this agent when designing API routes, database schemas, implementing geocoding logic, or solving reliability/security/performance issues in StarMapper's server-side code. Examples: adding a new API route, modifying Prisma schema, debugging geocoding cascade, optimizing the chunk endpoint.

not rated 83 2d ago A 0 tokens

security-patcher

207

FlorianBruniaux/starmapper

Agent Claude Code

Apply security patches from security-auditor findings. Requires audit report as input. Always proposes patches for human review — never applies without approval.

not rated 83 2d ago A 32 tokens

code-reviewer

208

hamzafarooq/multi-agent-course

Agent Claude Code

Scan code changes and flag security issues, logic errors, and missing tests. Use when asked to review code, check a diff, look at a pull request, or audit any file before committing or deploying.

not rated 80 1mo ago A 45 tokens

active-directory

209

mukul975/Threatswarm

Agent Claude Code

Active Directory and Windows domain attack specialist. Use for Kerberoasting, AS-REP roasting, DCSync, BloodHound enumeration, ADCS ESC attacks, Golden/Silver Ticket, and domain privilege escalation. Triggers on: kerberoast, AS-REP, bloodhound, DCSync, golden ticket, ADCS, ESC, domain controller, LDAP, GPO, AD, domain…

not rated 77 +2 4mo ago A 86 tokens original MIT

api-attacker

210

mukul975/Threatswarm

Agent Claude Code

API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignment, authentication bypass, rate limit evasion, JWT attacks, GraphQL introspection abuse, API enumeration, and OWASP API Top 10. Triggers on: API, REST, GraphQL, gRPC, WebSocket, BOLA, IDOR, mass assignment, API…

not rated 77 +2 4mo ago A 105 tokens original MIT

password-attacks

211

mukul975/Threatswarm

Agent Claude Code

Password cracking and credential attack specialist. Use when working with password hashes, hash cracking, wordlist attacks, credential analysis, or password auditing. Triggers on: password, hash, crack, hashcat, john, wordlist, NetNTLMv2, Kerberoast, NTLM, bcrypt, credential, ASREP, JWT crack, mask attack, rule…

not rated 77 +2 4mo ago A 88 tokens original MIT

GitHub Actions Expert

212

gitmotion/ntfy-me-mcp

Agent

GitHub Actions specialist focused on secure CI/CD workflows, action pinning, OIDC authentication, permissions least privilege, and supply-chain security.

not rated 72 4mo ago A 32 tokens GPL-3.0

quality-gate

213

edutrul/drupal-ai

Agent Claude Code

Static code review for security, performance, and quality. Read-only — no commands. Run before done-gate to catch issues before committing.

not rated 71 3mo ago A 32 tokens original MIT

Cluster Doctor

214

microsoftgbb/agentic-platform-engineering

Agent

An expert Kubernetes administrator agent specializing in cluster troubleshooting, networking, NetworkPolicy, security posture, admission controllers, and GitOps workflows. The agent assesses initial reports, independently verifies or rejects claims, triages root causes, and proposes or applies fixes (including GitOps…

not rated 71 2mo ago A 61 tokens fork Apache-2.0

security-reviewer

215

remiphilippe/mcp-unreal

Agent Claude Code

Use before any PR or release to audit security. Checks for path traversal, stdout pollution, credential leaks, and unsafe subprocess execution.

not rated 68 6mo ago A 30 tokens original Apache-2.0

orchestrator

216

SamarthaKV29/antigravity-god-mode

Agent

Multi-agent coordination and task orchestration. Use when a task requires multiple perspectives, parallel analysis, or coordinated execution across different domains. Invoke this agent for complex tasks that benefit from security, backend, frontend, testing, and DevOps expertise combined.

not rated 68 5mo ago A 53 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: