1,485 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,450Claude Code6,586Data and AI3,698Backend and APIs3,488Languages3,402Planning3,191Git and workflow3,129Code review2,728Memory and context2,353Testing2,330DevOps and cloud2,293Research2,288
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| rhaist/marq Universal cyber assistant: ~80 audited Kali tools + an expert skills library, driven by an | 4 | Claude Code | 1 | 3,553 tok |
| lewing/helix.mcp nuget.org CLI tool and MCP server for investigating .NET CI failures in Helix and Azure DevOps | 4 | Claude Code, Codex | 46 | — |
| camjac251/tool-gates camjac251.github.io Intelligent tool permission gate & security hooks for AI assistants (Claude Code, Codex, A | 4 | Claude Code, Codex, OpenCode | 3 | 2,051 tok |
| craigcossairt/trellis The structure a project grows on: a free starter template for AI-assisted development. One | 4 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 9 | 5,088 tok |
| toan203/osv-ui npmjs.com A beautiful, zero-config visual CVE dashboard for npm & Python. One command: npx osv-ui. 1 | 4 | Claude Code | 1 | — |
| Zenobia0000/ai-agentic-coding-template_unified | 4 | Claude Code | 9 | — |
| ysfAskri/archguardian Stop AI from slowly destroying your codebase. Tool-agnostic CLI + git pre-commit hook that | 4 | Claude Code, GitHub Copilot, Cursor | 36 | 1,619 tok |
| jgiox/goodvibes One command. Production-grade project. No config. | 4 | Claude Code, Codex, GitHub Copilot, Gemini CLI, Kiro, OpenCode, Windsurf | 15 | 6,796 tok |
| segraef/sec-kit Security Pre-flight Kit | 4 | Claude Code, GitHub Copilot | 3 | 942 tok |
| AliYmn/claude-structured An opinionated project template for Claude Code — persistent context, autonomous workflows | 4 | Claude Code, Codex, OpenCode | 6 | 534 tok |
| ralfyishere/agent-zero-trust Zero-trust repo intake for AI coding agents — scan the instruction environment before Clau | 4 | Claude Code | 1 | — |
| IvanTsxx/AI-Nextjs-Monorepo-Starter A modern, AI-first Next.js monorepo template equipped with PostgreSQL, Prisma, Better-Auth | 4 | Claude Code, GitHub Copilot, Gemini CLI | 4 | 4,440 tok |
| asaphe/promptcraft various rules, prompts and other settings used with various AI tools | 4 | Claude Code, Codex, OpenCode | 3 | 1,078 tok |
| florian101010/awesome-agentic-AI-coding-template Stop re-explaining your project to every AI agent. Pre-wired for Claude Code, Copilot, Cur | 4 | Claude Code, Codex, GitHub Copilot, Cursor, Gemini CLI, OpenCode | 26 | 3,985 tok |
| antonellof/s0-cli fratepietro.com Security-Zero: an LLM agent CLI that runs classic SAST scanners + AI-slop detectors, then | 4 | Claude Code | 1 | — |
| Parth308/auditx auditx-cli.vercel.app | 4 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 4 | 415 tok |
| Sting25/ai-coding-rules-scaffold Two-layer enforcement (pre-commit hook + CI mirror) for small teams using AI agents. Catch | 4 | Claude Code | 2 | — |
| Mazalucas/El-DT-Lightweight-Army El DT is the framework that turns your AI into a Technical Director: it structures the con | 4 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 5 | 1,144 tok |
| sublimotion/agent-aiops-on-aws Claude Code plugin for AWS infrastructure automation using Terraform with security scannin | 4 | Claude Code, Codex, OpenCode | 5 | 6,911 tok |
| mahuttha/offensive-recon Claude Code plugin — 8 skills + 2 agents for multi-phase offensive reconnaissance (nmap, n | 4 | Claude Code | 1 | 768 tok |
| reganomalley/claudia getclaudia.dev Proactive technology mentor plugin for Claude Code. 10 knowledge domains, 7 automated hook | 4 | Claude Code | 1 | 1,050 tok |
| ArabAgentSkills/arab-payments-skill-atlas AI agent skill atlas for safer Arab/MENA payment and BNPL integrations. | 4 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 803 tok |
| bop-clocktower/canary Canary — AI-powered test automation agent. Generate, review, recommend, and de-flake tests | 4 | Claude Code, Codex, OpenCode | 7 | 20,420 tok |
| chawdamrunal/assay chawdamrunal.github.io MCP & Claude Code security scanner — threat-models plugins, MCP servers, hooks, skills & c | 4 | Claude Code | 1 | 2,739 tok |
| raxITlabs/mcp-oauth-sample raxitai.github.io OAuth 2.1 authorization and MCP server on Vercel for MCP clients with real-time analytics | 4 | Claude Code, Gemini CLI | 2 | 1,409 tok |
| khizar-anjum/risky-business-mcp MCP server for finding out what level of vulnerability a CVE is | 4 | Claude Code | 1 | 25 tok |
| rdwj/mcp-test-mcp An MCP server for testing MCP servers | 4 | Claude Code | 3 | 1,168 tok |
| windoze95/servicewow-mcp ServiceNow MCP Server — per-user delegated access via OAuth 2.0 | 4 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 1,233 tok |
| Project-Navi/grippy-code-review project-navi.github.io AI-powered PR review agent with security rule engine, structured findings, and a grumpy au | 4 | Claude Code | 1 | 4,316 tok |
| jpcors/ring-mcp MCP server for Ring home security devices | 4 | Claude Code, Gemini CLI | 2 | 2,184 tok |
| quickvm/defined-mcp An unoffical MCP server for defined.net | 4 | Claude Code | 1 | — |
| agenthill/vaultpilot-mcp vaultpilot-mcp.ai Safety first. Hardware-verified DeFi for AI agents — designed for when the AI can be compr | 4 | Claude Code, Codex, OpenCode | 2 | 7,302 tok |
| achimstruve/mcp-https-OAuth-database-template A minimal MCP-HTTP-template that allows to distribute MCP server access via API-key author | 4 | Claude Code | 1 | 1,559 tok |
| gamittal-ak/alecs-mcp-server-akamai solutionsedge.io ALECS (A LaunchGrid for Edge & Cloud Services) is a community driven project creating a MC | 4 | Claude Code | 1 | 810 tok |
| cpoder/wm-mcp-server MCP server for managing webMethods Integration Server via pure HTTP API - 336 tools for fl | 4 | Claude Code | 1 | 3,580 tok |
| toyamagu-2021/argocd-mcp-server ArgoCD MCP Server | 4 | Claude Code | 2 | 1,795 tok |
| jaskaranhundal/usap-skills usap-security.vercel.app Open-source AI cybersecurity agent skills for SOC, incident response, threat hunting, red | 4 | Claude Code, Gemini CLI | 2 | 2,781 tok |
| alinotfoundbtw/sounding Governance for agent instructions: audit, score, and pin MCP servers, Agent Skills, and pr | 4 | Claude Code | 1 | 1,750 tok |
| KSEGIT/Version-Sentinel Claude Code plugin that hard-blocks dependency additions, bumps, and downgrades until a fr | 4 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 3,209 tok |
| reuvenaor/israel-statistics-mcp Israel Statistics MCP | 4 | Claude Code | 8 | 1,451 tok |
| thekie/read-no-evil-mcp A secure email gateway MCP server that protects AI agents from prompt injection attacks hi | 4 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 1,233 tok |
| blackfoxxx/Mobix Authorized Android pentest lab, drivable by hand or by AI — Frida bypass chain, live traff | 4 | Claude Code | 1 | — |
| badchars/supply-chain-mcp-server npmjs.com 90-tool MCP server for software supply chain security — OSV, GHSA, NVD, EPSS, CISA KEV, np | 4 | Claude Code | 1 | 550 tok |
| berntpopp/genefoundry-router genefoundry.org MCP gateway federating 21 biomedical MCP servers — gnomAD, ClinVar, HPO, UniProt, Ensembl | 4 | Claude Code, Codex, OpenCode | 12 | 1,672 tok |
| hexproofdev/oring Unprivileged, self-applied Landlock + seccomp confinement wrapper — no root, no daemon, on | 4 | Claude Code | 1 | 1,181 tok |
| MilindGaharwar/fettle pypi.org Open-source trust layer for AI coding agents: in-session quality, delegation-safe policy, | 4 | Claude Code, Codex, GitHub Copilot, OpenCode | 18 | 250 tok |
| femitfash/copilot-engine Reusable backend for building Claude-powered AI copilots with agentic tool use, SSE stream | 4 | Claude Code | 3 | 1,555 tok |
| 0xSoftBoi/suwappubot suwappu.bot Cross-chain DEX infrastructure for humans and AI agents — swap tokens across 14 chains via | 3 | Claude Code, Codex, OpenCode | 41 | 5,802 tok |
| aarifmms/keyblind keyblind.vercel.app keyblind | 3 | Claude Code | 1 | 923 tok |
| Mickdownunder/SafeInstall Open-source CLI that blocks risky npm, pnpm, and bun installs before they run. | 3 | Claude Code | 2 | — |