982 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,450Claude Code6,586Data and AI3,698Backend and APIs3,488Languages3,402Planning3,191Git and workflow3,129Code review2,728Memory and context2,353Testing2,330DevOps and cloud2,293Research2,288
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| Suzu-Testing/metasploit-cursor-harness Agentic penetration testing harness bridging Cursor AI agents with Metasploit Framework vi | 3 | Claude Code, Codex, Cursor, OpenCode | 63 | 2,469 tok |
| Nosmoht/talos-mcp-server MCP server for Talos Linux cluster management via the native gRPC API | 3 | Claude Code, Codex, OpenCode | 18 | 9,678 tok |
| nifrajs/nifra nifra.dev Full-stack TypeScript framework built for AI agents: typed server and client with no codeg | 3 | Claude Code, Codex, OpenCode | 2 | 2,352 tok |
| sukoji/loadout npmjs.com 🎯 Loadout — profile your project and gear up Claude Code with the right skills, MCP serve | 3 | Claude Code, Codex, OpenCode | 6 | 791 tok |
| Shad0wMazt3r/The-Scaffolding Solve CTF challenges, find bugs, better accuracy. Plug and play with any agent. | 3 | Claude Code, Codex, OpenCode | 2 | 1,137 tok |
| s977043/river-review river-review.the3396.com Turn reviews into organizational decision assets. Review Judgment as Code for AI-assisted | 3 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 10 | 9,600 tok |
| Mearman/agent-permissions Cross-agent permission policy for AI coding agents. MCP sync daemon, CLI, codecs, and eval | 3 | Claude Code, Codex, OpenCode | 2 | 4 tok |
| brandonkramer/trelly Trello CLI + MCP server with multi-profile auth. JSON output for scripts and AI agents. | 3 | Codex, OpenCode | 1 | 1,084 tok |
| oumaimah-QA/QIOS Structured QA skill framework for AI agents enabling consistent, risk-aware, and execution | 3 | Codex, OpenCode | 1 | 488 tok |
| snyk-labs/snyk-vulnbench | 3 | Claude Code, Codex, OpenCode | 12 | 2,521 tok |
| Enovatr-Labs/SpecRoute Open source framework for spec-driven agentic software engineering. PRDs, prompts, agents, | 3 | Claude Code, Codex, Gemini CLI, OpenCode | 7 | 3,090 tok |
| MMoMM-org/miyo-kado Where AI meets your vault, on your terms... Obsidian Vault MCP Server | 3 | Claude Code, Codex, OpenCode | 3 | 1,884 tok |
| wallidsaydi-creator/HOM-AIMOS hom.autos Agent-security system built on cryptographically auditable persistent memory, native retri | 2 | Codex, OpenCode | 1 | 231 tok |
| Agnuxo1/enigmagent-mcp npmjs.com Local encrypted vault MCP server. AES-256-GCM + Argon2id. Resolves {{PLACEHOLDER}} secrets | 2 | Codex, OpenCode | 1 | 481 tok |
| calllint/calllint calllint.com Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent | 2 | Codex, GitHub Copilot, OpenCode | 2 | 1,203 tok |
| matematicsolutions/mcp-saos matematicsolutions.com MCP server for Polish common and Supreme Court case law via the SAOS API - verifiable cita | 2 | Claude Code, Codex, OpenCode | 3 | 1,183 tok |
| AUTHENSOR/AUTHENSOR authensor.com We audit the instruments the AI industry measures itself with — and file every fix upstrea | 2 | Claude Code, Codex, Cursor, OpenCode | 3 | 2,309 tok |
| LeonMelamud/claude-code-security-review AI-powered security audit skill for code changes with false positive filtering. Based on A | 2 | Codex, OpenCode | 1 | 530 tok |
| raccioly/websec-validator pypi.org Local-first security recon that briefs your AI coding agent: facts + tailored probes, code | 2 | Codex, OpenCode | 1 | 1,080 tok |
| NexusOne23/noid-privacy-workstation noid-privacy.com 🛡️ Fully-hardened Security & Privacy OS based on Fedora 44 + GNOME · for Dev, Admin, Crea | 2 | Codex, OpenCode | 1 | 4,512 tok |
| drsh4dow/bevy-agent-feedback-plugin Let AI coding agents (Claude, Codex, Pi) see and control your Bevy game - remote input inj | 2 | Codex, OpenCode | 1 | 177 tok |
| php-workx/fuse A local firewall for AI agent commands | 2 | Claude Code, Codex, OpenCode | 2 | 2,996 tok |
| YankielDBC2/saas-cybersecurity Provider-aware Agent Skill for evidence-based SaaS security audits and regression-safe har | 2 | Codex, OpenCode | 1 | 335 tok |
| arcjet/skills Skills to make your AI coding agent an Arcjet security expert. | 2 | Codex, OpenCode | 1 | 688 tok |
| charliechenye/SkillGate chenyezhu.com Pre-merge and pre-install trust checks for AI-agent skills and MCP configurations. Scan ca | 2 | Codex, OpenCode | 1 | 477 tok |
| DjFikie25/shipkit Build full-stack Next.js and React Native apps with integrated auth, database, AI chat, an | 2 | Codex, OpenCode | 1 | 3,842 tok |
| yu-iskw/skill-inspector npmjs.com A sophisticated tool designed to bring quality and security to the world of AI Agent Skill | 2 | Claude Code, Codex, OpenCode | 2 | 617 tok |
| mirekondro/The-Pre-Flight-Check mirekondro.github.io ✈️ Stop your AI coding agent from declaring 'done' on broken code. Fail-fast quality gate: | 2 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 3,486 tok |
| cubxxw/agent-kit Public, versioned Agent Skills to safely bootstrap and sync Claude Code, Codex, Qwen Code, | 2 | Claude Code, Codex, OpenCode | 4 | 188 tok |
| rodrigopg/whatsapp-mcp WhatsApp MCP Server — community fork with LID contact fixes, group management, security ha | 2 | Claude Code, Codex, OpenCode | 2 | 865 tok |
| getskillseal/skillseal getskillseal.github.io Self-verifying agent skills. Your seal of approval. 🦭 | 2 | Claude Code, Codex, OpenCode | 2 | 751 tok |
| AbhiiGatty/cld-flare-maxxing cld-flare-maxxing.abhiigatty.com Claude Code and Codex plugin that audits, explains, and safely changes Cloudflare. Read-on | 2 | Claude Code, Codex, GitHub Copilot, OpenCode | 12 | 3,719 tok |
| vaquarkhan/kafka-mcp-enterprise-server vaquarkhan.github.io A production-ready Model Context Protocol (MCP) server for Apache Kafka. Features Informat | 2 | Codex, GitHub Copilot, Cursor, OpenCode | 5 | 1,155 tok |
| hexxla/mcp-ratchet Go package for enforcing tool call order in MCP servers. Token-based dependency system wit | 2 | Claude Code, Codex, OpenCode, Windsurf | 17 | 1,910 tok |
| salingnh/android-reverse-engineering-mcp Claude Code skill to support Android app's reverse engineering. (Safe) | 2 | Codex, OpenCode | 1 | 1,089 tok |
| waleedkhanbaloch/claude-code-safety-net waleedkhanbaloch.github.io 🛡️ Enhance code safety with Claude Code Safety Net, a tool designed to identify and mitig | 2 | Claude Code, Codex, OpenCode | 2 | 3,226 tok |
| Taibur-Rahaman/Agent2Wp-AI-WordPress-Agent Security engine for WordPress AI Abilities — fail-closed risk classification, permission g | 2 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 714 tok |
| rashidazarang/email-intel Email infrastructure fingerprinting for macOS | 2 | Claude Code, Codex, OpenCode | 2 | 619 tok |
| babywyrm/mcpnuke MCP red teaming & security scanner — enumerate, probe, and exploit Model Context Protocol | 2 | Codex, Cursor, OpenCode | 6 | 1,087 tok |
| aki0225/AgentToolGate A local AI Agent tool governance gateway: it does not prevent prompt injection, but preven | 2 | Claude Code, Codex, OpenCode | 2 | 807 tok |
| ArisRhiannon/vibecheck arisrhiannon.github.io Offline, no-AI "safe to ship?" gate for vibe-coded apps — finds the security mistakes AI c | 2 | Codex, OpenCode | 1 | 490 tok |
| decoy-run/decoy-redteam npmjs.com Autonomous red team for MCP servers. Sends adversarial payloads to your tools, proves expl | 2 | Codex, OpenCode | 1 | 1,499 tok |
| gordcurrie/unifi-mcp MCP server written in Go that exposes UniFi home-network operations as tools | 2 | Claude Code, Codex, GitHub Copilot, OpenCode | 4 | 2,346 tok |
| Coding-Dev-Tools/envault coding-dev-tools.github.io Sync, rotate, and manage .env files across environments securely | 2 | Codex, OpenCode | 1 | 584 tok |
| sdfdu/evopilot Local-first workflow compiler that turns repeated AI-agent work into evidence-backed, qual | 2 | Codex, OpenCode | 1 | 97 tok |
| 3z/hacktricks-mcp Fast, self-hostable MCP server giving AI agents token-authenticated full-text search over | 2 | Codex, OpenCode | 1 | 778 tok |
| ImBIOS/belifoa ⚡ High-performance, compact Linear client & MCP server for AI agents. Reduces prompt conte | 2 | Codex, OpenCode | 1 | 1,640 tok |
| Synapsor/Synapsor-Runner synapsor.ai Let AI agents query and update Postgres/MySQL without raw SQL, unrestricted schema access, | 2 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 1,188 tok |
| selfradiance/agentgate-governed-writefile-demo Smallest outsider-readable proof path through AgentGate + MCP Firewall: governed write_fil | 2 | Codex, OpenCode | 1 | 108 tok |
| albertik322-sudo/mcp-control-plane Open-source MCP 2.0 control plane for Windows, homelab, Docker, MikroTik, Home Assistant, | 2 | Claude Code, Codex, OpenCode | 3 | 163 tok |