1,481 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,410Claude Code6,578Data and AI3,695Backend and APIs3,487Languages3,404Planning3,188Git and workflow3,106Code review2,712Memory and context2,351Testing2,325Research2,289DevOps and cloud2,283
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| microsoft/entrabot microsoft.github.io Give a device-local AI agent its own Microsoft Entra identity. Reference implementation fo | 9 | Claude Code, Codex, OpenCode | 8 | 5,950 tok |
| Juwon1405/agentic-dart findevil.devpost.com Agentic-DART — autonomous detection & response agent. Architecture-first, not prompt-first | 9 | Claude Code, Codex, OpenCode | 2 | 2,541 tok |
| crunchtools/mcp-trentina Secure MCP server for quarantined web content extraction — two-layer defense against promp | 9 | Claude Code | 1 | 1,154 tok |
| creatornader/atrib atrib.dev Verifiable agent actions. Every action becomes signed context for the next. Ed25519 signat | 9 | Claude Code, Codex, OpenCode | 4 | 20,202 tok |
| KumaBase/agent-base | 9 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 7 | 3,029 tok |
| sourjya/kiro-rails Steering files, hooks, and workflow scripts that give Kiro AI coding agent persistent engi | 9 | Claude Code | 34 | — |
| karthikrshet/ClaudeMark Open-source, local-first AI watermark & provenance forensics platform — statistical detect | 9 | Claude Code, Codex | 1 | — |
| ArianHobson333/claude-bug-bounty-stack Complete Claude Code setup for bug bounty hunting — 99 skills, 22 slash commands, 10 agent | 9 | Claude Code | 1 | 500 tok |
| CaseyLabs/kc-secure-repo-template Security-hardened GitHub repository template, designed to prevent supply-chain attacks. In | 9 | Claude Code, Codex, OpenCode | 2 | 1,591 tok |
| jayelbotvibe-web/hermes-pentest-lab jayelbotvibe-web.github.io AI-orchestrated, Kali-native pentesting lab: an MCP tool-server with scope/VPN/rate/audit | 9 | Claude Code | 1 | 1,683 tok |
| Mocinjay/immunogen Static, offline-first security scanner for AI-built apps. 0–100 Ship Score across 11 categ | 9 | Claude Code | 1 | — |
| brandondees/code-quality-atlas From-first-principles research toward a standalone agent skill suite for code review & mai | 9 | Claude Code, Codex, OpenCode | 48 | 4,864 tok |
| AbdumajidRashidov/mycop abdumajidrashidov.github.io | 9 | Claude Code | 1 | 1,383 tok |
| MadaBurns/bv-mcp blackveilsecurity.com Open-source DNS & email security scanner. One MCP endpoint, 57 checks, zero install. Cloud | 9 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 17 | 13,051 tok |
| natesmalley/coral_collective The collective intelligence for evolutionary development - AI agents working as a unified | 9 | Claude Code | 11 | 556 tok |
| kaltinril/Kernsmith Cross-platform .NET library + CLI tool for generating bitmap fonts for games from TTF/OTF/ | 9 | Claude Code | 26 | 1,974 tok |
| aplaceforallmystuff/mcp-pihole MCP server for Pi-hole v6 API - control DNS blocking from Claude Code | 8 | Claude Code, Codex, Gemini CLI, OpenCode | 4 | 357 tok |
| whenpoem/aiscientist An AI-driven research workflow for generating ideas, running experiments, and writing scie | 8 | Claude Code, Codex, OpenCode | 6 | 1,865 tok |
| MrBinnacle/azimuth mrbinnacle.github.io Decision-quality pre-commitment analysis. Hosted at azimuth-testbed.netlify.app — no insta | 8 | Claude Code | 2 | — |
| iampantherr/SecureContext Persistent memory + security layer for Claude Code (MCP plugin). Agents remember your proj | 8 | Claude Code | 1 | 1,689 tok |
| berkcangumusisik/repo-seatbelt npmjs.com A safety layer for AI coding agents. CLAUDE.md/AGENTS.md generator, MCP runtime guardrail, | 8 | Claude Code, Codex, OpenCode | 2 | 1,503 tok |
| acartag7/mcp-sso OAuth 2.1 and enterprise SSO for remote MCP servers without API keys in client configs. | 8 | Claude Code, Codex, OpenCode | 4 | 4,794 tok |
| XuebinMa/AIWiki xuebinma.github.io AI-coding pitfalls & best practices, written from the AI's first-person POV — 76 entries a | 8 | Claude Code | 6 | 3,165 tok |
| shigechika/mcp-stdio Bidirectional stdio ↔ HTTP gateway for MCP servers — connect clients to remote servers or | 8 | Claude Code, GitHub Copilot | 2 | 6,962 tok |
| Pantheon-Security/chrome-mcp-secure Secure ChromeMCP Server - Query and Debugging sites using Google Chrome with additional se | 8 | Claude Code | 1 | 1,339 tok |
| vepo/issues Sistema de Gestão de Mudanças | 8 | Claude Code, Codex, Cursor, OpenCode | 25 | 4,153 tok |
| eriknewton/sanctuary-framework sanctuaryprotocol.ai Open-source security for AI agents: kernel-enforced egress control on macOS and Linux, key | 8 | Claude Code, Codex, OpenCode | 2 | 5,815 tok |
| bestagentkits/cloud-harness-mcp harness.agentkit.best Remote coding harness exposed as a secure Streamable HTTP MCP server | 8 | Claude Code, Codex, OpenCode | 3 | 1,743 tok |
| LLMTooling/code-search-mcp Model Context Protocol server providing powerful and efficient codebase search tools, incl | 8 | Claude Code | 6 | 1,476 tok |
| inoX-Network/claude-code-safety-guard 3-level override system for Claude Code - prevents destructive system operations. Born fro | 8 | Claude Code, Codex, OpenCode | 2 | 1,224 tok |
| Lex6won/vibecode-checker A first-line security linter for quickly AI-generated code, checking it against South Kore | 8 | Claude Code | 1 | — |
| PMDevSolutions/Aurelius A Claude Code toolkit for building React apps, from Figma designs to shipped product. Ship | 8 | Claude Code | 3 | 7,530 tok |
| snapsynapse/skill-provenance skillprovenance.dev Version identity and integrity verification for Agent Skills. Tracks versions, detects sta | 7 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 2,306 tok |
| OpenLatch/saferskills saferskills.ai Every AI skill, independently scanned. Public, open-source trust scoring for skills, MCP s | 7 | Claude Code | 5 | 2,592 tok |
| L-X-T/ng-agentic A practical Angular workspace starter with modern best practices, AI-ready tooling, and sc | 7 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 4 | 2,522 tok |
| BrainWeb/payload-mcp-oauth npmjs.com OAuth 2.1 + PKCE + Dynamic Client Registration for Payload CMS MCP, so it connects to the | 7 | Claude Code | 2 | 864 tok |
| steve-magne/hookstack hookstack.app Claude Code hooks catalogue — production-ready hooks for Claude Code, OpenAI Codex & GitHu | 7 | Claude Code, Codex, OpenCode | 28 | 9,006 tok |
| taniwhaai/arai arai.taniwha.ai Your AI assistant reads CLAUDE.md and ignores it anyway. Ārai makes instruction files enfo | 7 | Claude Code, Codex, OpenCode | 11 | 4,831 tok |
| tb0hdan/wass-mcp Web Application Security Scanner MCP Server | 7 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 191 tok |
| frootai/frootai frootai.dev From the Roots to the Fruits ! | 7 | Claude Code, Codex, GitHub Copilot, OpenCode | 8 | 9,604 tok |
| Diplomat-ai/diplomat-agent diplomat.run What can your AI agent do to the real world? Scan your code. See which tool calls have zer | 7 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 1,004 tok |
| raunakkathuria/buildwright Approve intent, ship autonomously. Agent-first autonomous development workflow for Claude | 7 | Claude Code, Codex, OpenCode | 2 | 1,579 tok |
| Zenobia000/ai-agentic-coding-template_unified | 7 | Claude Code | 9 | — |
| actual-software/actual-cli cli.actual.ai | 7 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 1,269 tok |
| P4ST4S/mcp-audit A transparent Go proxy that intercepts, signs, and audits all MCP tool calls between any c | 7 | Claude Code, Codex, OpenCode | 2 | 2,446 tok |
| abdullahkhawer/devops-skills A curated collection of DevOps Skills that enhance your development using AI to work smart | 7 | Claude Code | 1 | — |
| jgardner04/Ghost-MCP-Server An MCP Server for managing posts on Ghost CMS | 7 | Claude Code | 1 | 5,985 tok |
| ca-risken/risken-mcp-server RISKEN's official MCP Server | 7 | Claude Code | 1 | 1,322 tok |
| aplaceforallmystuff/mcp-threatintel MCP server for unified threat intelligence - AlienVault OTX, AbuseIPDB, GreyNoise, and abu | 7 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 538 tok |
| artvepa80/Agents-Hefesto hefestoai.narapallc.com AI-powered code quality agent with ML semantic analysis. Prevents technical debt before p | 7 | Claude Code, GitHub Copilot | 2 | 5,503 tok |