1,029 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,410Claude Code6,578Data and AI3,695Backend and APIs3,487Languages3,404Planning3,188Git and workflow3,106Code review2,712Memory and context2,351Testing2,325Research2,289DevOps and cloud2,283
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| abl030/pfsense-mcp MCP server for the pfSense REST API v2 — 677 tools for AI-driven firewall management | 1 | Claude Code, Codex, OpenCode | 2 | 2,909 tok |
| Raed2180416/holt raed2180416.github.io See what coding agents changed across Git worktrees. Inspect duplicates, collisions and de | 1 | Claude Code, Codex, OpenCode | 5 | 1,120 tok |
| berntpopp/mgi-link genefoundry.org MCP server for MGI (Mouse Genome Informatics): mouse gene, allele, mutation and phenotype | 1 | Claude Code, Codex, OpenCode | 10 | 1,930 tok |
| yigitkonur/mcp-supersubagents MCP server for spawning and managing parallel AI agents. Run multiple autonomous Copilot s | 1 | Claude Code, Codex, GitHub Copilot, OpenCode | 9 | 9,778 tok |
| berntpopp/hpo-link genefoundry.org MCP server for the Human Phenotype Ontology (HPO): phenotype term lookup, the is_a hierarc | 1 | Claude Code, Codex, OpenCode | 10 | 3,019 tok |
| ex-nihilo-labs/agent-auth Zero-knowledge credential injection for AI agents. MCP server — agents authenticate withou | 1 | Codex, OpenCode | 1 | 784 tok |
| yamayued/j-platpat-mcp MCP server scaffold for the official JPO patent information acquisition API | 1 | Codex, OpenCode | 1 | 619 tok |
| dr-code/tessera Persistent codebase memory for Claude Code — open source MCP server | 1 | Claude Code, Codex, OpenCode | 14 | 3,241 tok |
| SinoEdwards/mail-agent-mcp Local-first email MCP server for Gmail and QQ Mail with secure OAuth, IMAP search/read, at | 1 | Claude Code, Codex, OpenCode | 2 | 967 tok |
| RZFL/agentops-mcp Local-first MCP safety agent for AI coding workflows with checkpoints and rollback. | 1 | Codex, OpenCode | 1 | 271 tok |
| konstruktoid/prescryb MCP server for CVE/config remediation orchestration: SSH inventory, OSV/NVD lookups, CIS/D | 1 | Claude Code, Codex | 4 | 740 tok |
| Ailian0206/mcp-guardian Pre-call MCP tool policy gateway: allow / deny / redact / require_approval | 1 | Claude Code, Codex, OpenCode | 2 | 465 tok |
| arojit/vulnpilot-mcp An MCP server that gives AI assistants the ability to check open-source packages for vulne | 1 | Claude Code, Codex | 1 | — |
| Ylyass/mcp-privilege-profiler Task-scoped least-privilege security proxy and Wazuh detection bridge for MCP-based AI age | 1 | Codex, OpenCode | 1 | 172 tok |
| nabheet/google-services-mcp MCP server for Google consumer services — Gmail, Calendar, Drive, Sheets, Docs, Slides, Yo | 1 | Codex, OpenCode | 1 | 1,393 tok |
| gugu9999gu/PC-CONTROL-MCP | 1 | Claude Code, Codex, GitHub Copilot, OpenCode | 9 | 2,466 tok |
| danveil/mcp-security-inspector Explainable static security analysis for MCP tool metadata, including tool-poisoning indic | 1 | Codex, OpenCode | 1 | 560 tok |
| hygef-v4/youtube-studio-mcp hygef-v4.github.io High-performance, zero-dependency MCP server connecting AI assistants (Claude, Cursor, Ant | 1 | Claude Code, Codex, OpenCode | 2 | 5,542 tok |
| jakub-lapinski/google-calendar-mcp-serviceaccount Minimal Google Calendar MCP server authenticated via a service account — no OAuth consent | 1 | Codex, OpenCode | 1 | 1,179 tok |
| avivancos/open-english OLCP - a portable MCP server that owns identity, curriculum and the learner model, while a | 1 | Claude Code, Codex, OpenCode | 8 | 2,863 tok |
| cyanheads/osv-advisory-mcp-server npmjs.com Query OSV.dev for package vulnerabilities, batch-audit dependency lists, and fetch full ad | 1 | Claude Code, Codex, OpenCode | 2 | 10,830 tok |
| cyanheads/pentest-mcp-server npmjs.com Offline methodology engine and payload workshop for authorized penetration testing, CTF, s | 1 | Claude Code, Codex, OpenCode | 2 | 10,384 tok |
| cyanheads/nist-nvd-mcp-server npmjs.com Search and audit CVEs by keyword, severity, CWE, CISA KEV status, and CPE via the NIST Nat | 1 | Claude Code, Codex, OpenCode | 2 | 12,890 tok |
| cyanheads/attack-surface-mcp-server npmjs.com Passive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS | 1 | Claude Code, Codex, OpenCode | 2 | 13,280 tok |
| cyanheads/nws-weather-mcp-server npmjs.com Real-time US weather data via the National Weather Service API. Forecasts, alerts, and obs | 1 | Claude Code, Codex, OpenCode | 2 | 11,574 tok |
| drmf-cz/claude-beacon Claude Code MCP channel plugin — pushes GitHub Actions CI/CD results into running Claude C | 1 | Claude Code, Codex, OpenCode | 5 | 5,239 tok |
| zai-one/telegram-ads-mcp zai.one Unofficial MCP server for Telegram Ads (TON cabinet, Gram currency). For Claude, Cursor, a | 1 | Claude Code, Codex, OpenCode | 2 | 2,892 tok |
| purinzan/gx3-cli-mcp zenn.dev Trace a GX Works3 ladder without opening GX Works3 — read-only CLI + MCP server so anyone | 1 | Codex, OpenCode | 1 | 358 tok |
| aikadimsoy/kasa-mcp KASA MCP — a permission-brokered MCP server for agent memory. Local-first, encrypted at th | 1 | Claude Code, Codex, OpenCode | 3 | 1,870 tok |
| KevinTrinhDev/gaze It sees the page, and it acts. Drive a real, already logged-in browser from the CLI or ove | 1 | Codex, OpenCode | 1 | 1,394 tok |
| NexgenSystemsMX/scopegate Ephemeral credentials & persistent MCP connections for coding agents — the agent never hol | 0 | Claude Code, Codex, OpenCode | 2 | 3,678 tok |
| TheNickSanchez/passkey-mcp Cross-platform secrets manager for AI coding assistants — stores secrets in system keychai | 0 | Codex, OpenCode | 1 | 2,282 tok |
| ayhammouda/obd-mcp-server Safety-first, read-only MCP server for vehicle diagnostics with simulator-first OBD-II, EL | 0 | Codex, OpenCode | 1 | 489 tok |
| dinglebear-ai/connexin Connexin — human-approved SSH shell and file transfer as an MCP App | 0 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 265 tok |
| omamishra8051-source/PenTest-MCP | 0 | Claude Code, Codex, OpenCode | 2 | 289 tok |
| Jackson-DM/msp-tools-mcp | 0 | Claude Code, Codex, OpenCode | 3 | 193 tok |
| rosselps/whyguard npmjs.com Reconstructs why code exists and stops humans or agents from erasing that protection by ac | 0 | Claude Code, Codex, Kiro, OpenCode | 6 | 4,673 tok |
| frli4797/crowdsec-mcp CrowdSec-focused MCP server for safe, auditable security operations. | 0 | Codex, OpenCode | 1 | 945 tok |
| kappa9999/white-hat-agent Model-neutral cyber knowledge, orchestration, discovery, and MCP application layer for AI | 0 | Codex, OpenCode | 1 | 298 tok |
| whoismemas/burpsuite-for-ai-agent Two-way Burp Suite MCP bridge for AI agents — capture traffic, queue scan tasks, send find | 0 | Codex, OpenCode | 1 | 867 tok |
| saagpatel/shadow-mcp Discover and risk-grade the MCP servers present on this machine (local-first OWASP MCP09 s | 0 | Codex, OpenCode | 1 | 196 tok |
| scanmalware/mcp-server MCP server for the ScanMalware.com API | 0 | Codex, OpenCode | 1 | 1,550 tok |
| BackBond/agent-scan backbond.ai Vet MCP and AI-agent tools before attachment. Local, deterministic static scanning with no | 0 | Codex, OpenCode | 1 | 825 tok |
| DrBaher/sign-cli cli.drbaher.com Agent-first e-signature CLI. Fully-offline PAdES signer (PKCS#7) — no signup — or hosted p | 0 | Codex, OpenCode | 1 | 1,179 tok |
| antonillos/safeselect antonillos.github.io Read-only PostgreSQL & MongoDB access for coding agents. Local, fail-closed MCP enforcemen | 0 | Codex, OpenCode | 1 | 619 tok |
| cristianmoroaica/bountyverdict cristianmoroaica.github.io Seven x402 decision APIs and installable agent skills for GitHub bounties, CI, skill secur | 0 | Codex, OpenCode | 1 | 324 tok |
| davidmosiah/delx-agent-utilities ontology.delx.ai Open-source stateless utility tools for AI agents: URL, DNS, TLS, OpenAPI, x402, JWT, CSV/ | 0 | Codex, OpenCode | 1 | 248 tok |
| dir-ai/repotector ⬡ The repo guardian AI agents handshake with before they touch your code. Handshake-first | 0 | Claude Code, Codex, GitHub Copilot, OpenCode | 4 | 648 tok |
| elberacasa/umbra umbra-badge.umbrabadge.workers.dev The trust score for AI-generated code. One command verifies what your coding agent shipped | 0 | Claude Code, Codex, OpenCode | 1 | 933 tok |
| laser54/telegram-managed-bot-factory Secure self-hosted MCP control plane for owner-confirmed Telegram bot provisioning. | 0 | Codex, OpenCode | 1 | 373 tok |