1,481 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,410Claude Code6,578Data and AI3,695Backend and APIs3,487Languages3,404Planning3,188Git and workflow3,106Code review2,712Memory and context2,351Testing2,325Research2,289DevOps and cloud2,283
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| shenjingnan/haimen Enter through this door, exit through that door. | 7 | Claude Code, Codex, OpenCode | 7 | 2,038 tok |
| erlef-cna/varsel Varsel is the software behind the EEF CNA. | 7 | Claude Code, Codex, OpenCode | 2 | 22,996 tok |
| ramboz/jig A Claude Code and Codex plugin that scaffolds AI-native development practices into new pro | 6 | Claude Code, Codex, OpenCode | 8 | 6,703 tok |
| martinhavel/cz-agents-mcp cz-agents.dev Czech & EU due-diligence / KYC-AML MCP servers — sanctions (EU+OFAC), insolvency (ISIR), V | 6 | Claude Code | 6 | — |
| paolovella/vellaveto Agentic security control plane for MCP and AI agent tool calls. MCP-native policy gateway | 6 | Claude Code | 1 | 9,041 tok |
| ArmisSecurity/armis-appsec-mcp AI-powered security scanning MCP plugin for Claude Code | 6 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 6,233 tok |
| suyogpawar88/Threat-Model suyogpawar88.github.io | 6 | Claude Code, Codex, OpenCode | 1 | 1,275 tok |
| chenyuxiaojin/cyxj-remotion-starter A workbench scaffold for directing Remotion to create videos with Claude Code: three-layer | 6 | Claude Code | 6 | 1,319 tok |
| FavioVazquez/mollify Deterministic codebase intelligence for Python | 6 | Claude Code, Codex, Cursor, Gemini CLI, OpenCode | 24 | 4,352 tok |
| mtnyilmaz/agents | 6 | Claude Code, Codex, OpenCode | 57 | 2,391 tok |
| morooka-akira/aicm | 6 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 10 | 9,770 tok |
| PoulpYBifle/NCF-Coding-Best-Practices | 6 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 7,859 tok |
| Contoso-State/red-team-agent-orchestration | 6 | Claude Code, Codex, OpenCode | 47 | 2,697 tok |
| nerviq/nerviq nerviq.net Your agent docs lie. Nerviq finds the lies in 30 seconds — stale references, permission ex | 6 | Claude Code, Codex, OpenCode | 15 | 2,959 tok |
| danielealbano/mcp-for-azure-devops-boards A Model Context Protocol (MCP) server for interacting with Azure DevOps Boards and Work It | 6 | Claude Code | 2 | — |
| mbeato/APIMesh apimesh.xyz APIMesh — 23 pay-per-call web analysis APIs + 16-tool MCP server with autonomous API gener | 6 | Claude Code | 1 | 723 tok |
| x746b/mem_forensics-mcp Unified Memory Forensics MCP Server - Multi-tier engine combining Rust speed with Vol3 cov | 6 | Claude Code | 1 | 1,224 tok |
| x746b/mac_forensics-mcp MCP server for macOS Digital Forensics and Incident Response (DFIR) | 6 | Claude Code | 1 | 2,692 tok |
| DunkelCloud/ToolMesh toolmesh.io Self-hosted MCP gateway with authorization, credential injection, audit logging, and outpu | 6 | Claude Code | 1 | 1,297 tok |
| aarora79/claude-code-usage-analyzer Comprehensive cost & token usage analyzer for Claude Code with detailed breakdowns by mode | 6 | Claude Code | 3 | 2,771 tok |
| badchars/dns-security-mcp npmjs.com 104-tool DNS Security Intelligence MCP Server — DNSSEC, hijacking, tunneling, typosquattin | 6 | Claude Code | 1 | 444 tok |
| PacktPublishing/The-Claude-Code-Operating-Model The Claude Code Operating Model, published by Packt | 6 | Claude Code | 1 | — |
| mukul975/BHUSA-Anthropic-CyberSecurity-Skills | 6 | Claude Code | 1 | 220 tok |
| JoeDelaney1111/Awsome-Skills-Claude | 6 | Claude Code | 1 | — |
| omkhar/vulnerability-validation-skill | 6 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 5 | 3,231 tok |
| brainbytes-dev/nextjs-expo-saas-starter Ship web + mobile SaaS in days. Next.js 16 · Expo SDK 55 · Stripe · RevenueCat · Better-Au | 6 | Claude Code | 1 | 2,183 tok |
| yu-iskw/llmops-demo-ts Demonstrate LLMOps in TypeScript | 6 | Claude Code, Cursor | 29 | 1,463 tok |
| lucaspressi/claudekit-engineer | 6 | Claude Code, Codex, Gemini CLI, OpenCode | 10 | 2,006 tok |
| mrgnhnt96/sip A command-line tool to manage Dart mono-repos. | 5 | Claude Code, Codex, OpenCode | 7 | 2,533 tok |
| goklab/guardvibe guardvibe.dev Security infrastructure your AI can't be — deterministic, daily CVE intel past your model' | 5 | Claude Code | 1 | 597 tok |
| pleasedodisturb/llm-safe-haven One-liner for AI solo developers to fasten the security bolts on their systems | 5 | Claude Code, Codex, OpenCode | 2 | 2,287 tok |
| christopherlouet/claude-base christopherlouet.github.io Opinionated Claude Code foundation — Explore → TDD → Audit workflow, auto-detected stack p | 5 | Claude Code | 18 | — |
| pitimon/claude-cybersecurity-skill Claude Code plugin — 18 cybersecurity domains: IR, DFIR, DevSecOps, SOC, Code Security, Co | 5 | Claude Code | 1 | 1,816 tok |
| jlevy/supply-chain-hardening Supply-chain payloads run at install, import, or repo-open time. Copy-pasteable hardening | 5 | Claude Code, Codex, OpenCode | 6 | 1,947 tok |
| turenlabs/batou batousast.com Batou catches risky code while Claude Code is writing files, before bad code lands in your | 5 | Claude Code | 4 | 6,718 tok |
| jmagar/swag-mcp SWAG reverse proxy configuration management via MCP. Create, edit, view, and manage nginx | 5 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 2,374 tok |
| thiagolmoraes/leash Sandbox to run AI coding agents (Claude Code, Codex, Gemini, Grok) with full TLS inspectio | 5 | Claude Code | 2 | — |
| 2389-research/fresh-eyes-review 2389-research.github.io Mandatory final sanity check before commits/PRs - catches security vulnerabilities, logic | 5 | Claude Code | 1 | 814 tok |
| rbah31/claude-code-workflow A structured, sprint-based workflow for AI-assisted development with Claude Code. | 5 | Claude Code | 5 | — |
| zebbern/termstack An open-source agentic vibe coding platform that helps you build your own platform (Claude | 5 | Claude Code, GitHub Copilot | 12 | 15,538 tok |
| NFTYoginis/agency-of-one nftyoginis.github.io A Claude Code template for running a content/design business as a solo operator. One orche | 5 | Claude Code | 4 | 1,973 tok |
| yunsii/wezdeck A flight deck for your AI agents — multi-agent terminal platform built on WezTerm + tmux + | 5 | Claude Code, Codex, OpenCode | 4 | 4,379 tok |
| trongnguyenbinh/zalo-bot-mcp MCP channel server for the Zalo Bot API. Talk to your Claude Code session from Zalo, with | 5 | Claude Code | 8 | — |
| MangroveTechnologies/mangrove-agent mangrovedeveloper.ai Claude agent for use with the Mangrove Developer API & MCP Server. | 5 | Claude Code | 5 | 874 tok |
| Sandeeprdy1729/timps timps-website.vercel.app The AI memory layer with 17 intelligence tools — catches contradictions, predicts burnout, | 5 | Claude Code, Codex, OpenCode | 2 | 24,407 tok |
| xChechi/xche-ai-app-security-pack stefannasev.dev Free security guardrails for apps built with AI coding tools (Claude Code, Cursor, Lovable | 5 | Claude Code, Codex, OpenCode | 2 | 1,527 tok |
| TyrusRC/praetor Agentic pentest & red-team harness via Burp Suite MCP toolkit | 5 | Claude Code, Codex, OpenCode | 2 | 8,151 tok |
| danygiguere/audit-skills Language- and framework-agnostic audit checklists for AI coding agents — security, correct | 5 | Claude Code, Codex, OpenCode | 2 | 2,553 tok |
| zebbern/pocmap zebbern.github.io MCP-native CVE, PoC & exploit discovery toolkit (Metasploit, Nuclei, GitHub & more) | 5 | Claude Code, Codex, OpenCode | 2 | 4,679 tok |
| badarosama/mcp-control-plane Policy-based authorization middleware for MCP servers. Role-based tool filtering, call enf | 5 | Claude Code | 1 | 30 tok |