2,106 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,412Data and AI4,299Backend and APIs3,694Languages3,682Planning3,492Git and workflow3,285Code review2,942Memory and context2,581Research2,499Writing and docs2,458Testing2,454Frontend2,420
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorKiroWindsurf
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| affaan-m/ECC ecc.tools The agent harness performance optimization system. Skills, instincts, memory, security, an | 250,130 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 3,778 tok |
| electron/electron electronjs.org :electron: Build cross-platform desktop apps with JavaScript, HTML, and CSS | 122,901 | Claude Code, GitHub Copilot | 8 | 4,327 tok |
| usestrix/strix strix.ai Open-source AI penetration testing tool to find and fix your app’s vulnerabilities. | 60,777 | Codex, OpenCode | 1 | 1,847 tok |
| colinhacks/zod zod.dev TypeScript-first schema validation with static type inference | 43,847 | Claude Code, Codex, Cursor, OpenCode | 5 | 5,780 tok |
| danny-avila/LibreChat librechat.ai Enhanced ChatGPT Clone: Features Agents, MCP, Skills, DeepSeek, Anthropic, AWS, OpenAI, Re | 42,847 | Claude Code, Codex, OpenCode | 2 | 4,147 tok |
| rapid7/metasploit-framework metasploit.com Metasploit Framework | 38,946 | Codex, GitHub Copilot, OpenCode | 6 | 7,425 tok |
| zhaoxuya520/reverse-skill Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack | 34,719 | Claude Code, Codex, OpenCode | 2 | 1,078 tok |
| nicolargo/glances nicolargo.github.io Glances an Eye on your system. A top/htop alternative for GNU/Linux, BSD, macOS and Window | 33,526 | Claude Code | 3 | 1,149 tok |
| OWASP/CheatSheetSeries cheatsheetseries.owasp.org The OWASP Cheat Sheet Series was created to provide a concise collection of high value inf | 33,087 | Claude Code, Codex, OpenCode | 2 | 2,094 tok |
| mukul975/Anthropic-Cybersecurity-Skills mahipal.engineer 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, | 32,252 | Codex, GitHub Copilot, OpenCode | 2 | 5,015 tok |
| agentscope-ai/agentscope docs.agentscope.io Build and run agents you can see, understand and trust. | 30,816 | GitHub Copilot | 1 | 741 tok |
| trufflesecurity/trufflehog trufflesecurity.com Find, verify, and analyze leaked credentials | 27,694 | Cursor | 1 | — |
| activepieces/activepieces activepieces.com AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automati | 24,286 | Claude Code, Codex, OpenCode | 22 | 9,534 tok |
| semgrep/semgrep semgrep.dev Lightweight static analysis for many languages. Find bug variants with patterns that look | 16,525 | Claude Code, Codex, OpenCode | 2 | 2,020 tok |
| analysis-tools-dev/static-analysis analysis-tools.dev ⚙️ A curated list of static analysis (SAST) tools and linters for all programming language | 14,766 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 4 | 344 tok |
| prowler-cloud/prowler prowler.com Prowler is the world’s most widely used open-source cloud security platform that automates | 14,759 | Claude Code, Codex, OpenCode | 2 | 2,928 tok |
| casdoor/casdoor casdoor.ai An open-source Agent-first Identity and Access Management (IAM) /LLM MCP & agent gateway a | 14,347 | Claude Code | 1 | 37 tok |
| qazbnm456/awesome-web-security awesomelists.top 🐶 A curated list of Web Security materials and resources. | 13,772 | Claude Code | 1 | 3,273 tok |
| blackboardsh/electrobun blackboard.sh Build ultra fast, tiny, and cross-platform desktop apps with Typescript. | 12,762 | Claude Code, Codex | 2 | 371 tok |
| TencentCloud/CubeSandbox cubesandbox.com Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents. | 11,808 | Claude Code, Codex, OpenCode | 11 | 232 tok |
| data-privacy-stack/presidio presidio.dataprivacystack.org An open-source framework for detecting, redacting, masking, and anonymizing sensitive data | 10,747 | Claude Code, Codex, GitHub Copilot, OpenCode | 5 | 6,710 tok |
| xonsh/xonsh xon.sh 🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly. | 9,633 | Claude Code | 1 | 6 tok |
| NVIDIA/garak discord.gg the LLM vulnerability scanner | 9,120 | Codex, OpenCode | 1 | 1,415 tok |
| NVIDIA/OpenShell docs.nvidia.com OpenShell is the safe, private runtime for autonomous AI agents. | 8,517 | Claude Code, Codex, OpenCode | 22 | 4,796 tok |
| backnotprop/plannotator plannotator.ai Annotate and review coding agent plans and code diffs visually, share with your team, send | 8,463 | Claude Code, Codex, OpenCode | 6 | 35,880 tok |
| kunchenguid/no-mistakes kunchenguid.github.io git push no-mistakes | 8,312 | Claude Code, Codex, OpenCode | 17 | 5,764 tok |
| superradcompany/microsandbox docs.microsandbox.dev 🧱 easy fast local-first microVM runtime and library | 8,091 | Codex, OpenCode | 1 | 3,652 tok |
| zeek/zeek zeek.org Zeek is a powerful network analysis framework that is much different from the typical IDS | 7,941 | Codex, OpenCode | 1 | 823 tok |
| vercel-labs/deepsec deepsec.sh Deepsec is a security harness for finding vulnerabilities in your codebase powered by codi | 7,917 | Claude Code | 1 | 411 tok |
| anthropics/defending-code-reference-harness claude.com Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harnes | 7,409 | Claude Code | 2 | 4,052 tok |
| trailofbits/skills Trail of Bits Claude Code skills for security research, vulnerability detection, and audit | 6,978 | Claude Code, Codex, OpenCode | 2 | 4,752 tok |
| j3ssie/osmedeus osmedeus.org A Modern Orchestration Engine for Security | 6,549 | Claude Code, Codex, OpenCode | 2 | 8,804 tok |
| MISP/MISP misp-project.org MISP (core software) - Open Source Threat Intelligence and Sharing Platform | 6,503 | Claude Code | 1 | 1,817 tok |
| lldap/lldap Light LDAP implementation | 6,488 | GitHub Copilot | 1 | 1,992 tok |
| microsoft/agent-governance-toolkit AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxin | 6,204 | Codex, GitHub Copilot, OpenCode | 2 | 7,473 tok |
| anthropics/claude-code-security-review An AI-powered security review GitHub Action using Claude to analyze code changes for secur | 6,170 | Claude Code | 1 | — |
| Tencent/AI-Infra-Guard tencent.github.io A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, M | 6,151 | Claude Code, Codex, OpenCode | 2 | 2,177 tok |
| FlorianBruniaux/claude-code-ultimate-guide cc.bruniaux.com The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, q | 5,903 | Claude Code, Codex, GitHub Copilot, OpenCode | 10 | 5,911 tok |
| mock-server/mockserver-monorepo mock-server.com MockServer is an HTTP(S) mock server and proxy for testing that lets you mock APIs, inspec | 4,965 | Claude Code, Codex, OpenCode | 61 | 7,403 tok |
| Awarexone/Agentic-Bug-Hunter awarexone.com AI-powered bug bounty hunting toolkit that works with or without subscription. | 4,710 | Claude Code, Codex, OpenCode | 4 | 5,851 tok |
| mvanhorn/cli-printing-press Every API has a secret identity. This finds it, absorbs every feature from every competing | 4,635 | Claude Code, Codex, OpenCode | 4 | 10,111 tok |
| firebase/firebase-tools The Firebase Command Line Tools | 4,463 | Claude Code, Codex, Gemini CLI | 3 | 769 tok |
| intuitem/ciso-assistant-community intuitem.com CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & A | 4,410 | Claude Code | 5 | — |
| dmno-dev/varlock varlock.dev AI-safe .env files: Schemas for agents, Secrets for humans. | 4,298 | Claude Code, Codex, GitHub Copilot, OpenCode | 6 | 2,320 tok |
| nolabs-ai/nono nono.sh secure multiplexed execution paths for agents - zero trust, zero setup, zero latency. | 3,978 | Claude Code, Codex, OpenCode | 2 | 2,527 tok |
| ilysenko/codex-desktop-linux Unofficial ChatGPT desktop app for Linux (formerly the Codex app), built locally from Open | 3,769 | Codex, OpenCode | 1 | 1,444 tok |
| gadievron/raptor Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By | 3,714 | Claude Code | 6 | 9,375 tok |
| nextlevelbuilder/goclaw goclaw.sh GoClaw - GoClaw is OpenClaw rebuilt in Go — with multi-tenant isolation, 5-layer security, | 3,589 | Claude Code, Codex, OpenCode | 2 | 12,319 tok |
| cool-team-official/cool-admin-midway cool-js.com 🔥 cool-admin (Midway edition), a powerful backend permission management framework featuri | 3,270 | Cursor | 1 | 807 tok |
| langchain-ai/langgraphjs docs.langchain.com Framework to build resilient language agents as graphs. | 3,251 | Claude Code, Codex, OpenCode | 2 | 551 tok |