1,995 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,473Claude Code6,589Data and AI3,693Backend and APIs3,491Languages3,403Planning3,201Git and workflow3,131Code review2,731Memory and context2,354Testing2,335DevOps and cloud2,298Research2,288
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| kristianedlund/hardcover-mcp MCP server for the Hardcover book tracking API - search books, manage your library, lists, | 6 | Claude Code, GitHub Copilot | 3 | 2,313 tok |
| draugr-dev/draugr draugr.dev Run Trivy, Semgrep, Gitleaks and more from one file. Consolidates SAST, SCA, secrets, IaC | 6 | Claude Code | 1 | 2,798 tok |
| trueoriginlabs/vibatchium pypi.org Stealth browser automation for AI agents — unattended, headless, N parallel persistent log | 6 | Codex, OpenCode | 1 | 9,802 tok |
| yu-iskw/llmops-demo-ts Demonstrate LLMOps in TypeScript | 6 | Claude Code, Cursor | 29 | 1,463 tok |
| lucaspressi/claudekit-engineer | 6 | Claude Code, Codex, Gemini CLI, OpenCode | 10 | 2,006 tok |
| mrgnhnt96/sip A command-line tool to manage Dart mono-repos. | 5 | Claude Code, Codex, OpenCode | 7 | 2,533 tok |
| goklab/guardvibe guardvibe.dev Security infrastructure your AI can't be — deterministic, daily CVE intel past your model' | 5 | Claude Code | 1 | 597 tok |
| doc2mcp/doc2mcp doc2mcp.vercel.app Paste any docs URL — LangChain, Stripe, your own — and get a hosted MCP server Cursor can | 5 | Cursor | 1 | — |
| pleasedodisturb/llm-safe-haven One-liner for AI solo developers to fasten the security bolts on their systems | 5 | Claude Code, Codex, OpenCode | 2 | 2,287 tok |
| christopherlouet/claude-base christopherlouet.github.io Opinionated Claude Code foundation — Explore → TDD → Audit workflow, auto-detected stack p | 5 | Claude Code | 18 | — |
| pitimon/claude-cybersecurity-skill Claude Code plugin — 18 cybersecurity domains: IR, DFIR, DevSecOps, SOC, Code Security, Co | 5 | Claude Code | 1 | 1,816 tok |
| jlevy/supply-chain-hardening Supply-chain payloads run at install, import, or repo-open time. Copy-pasteable hardening | 5 | Claude Code, Codex, OpenCode | 6 | 1,947 tok |
| turenlabs/batou batousast.com Batou catches risky code while Claude Code is writing files, before bad code lands in your | 5 | Claude Code | 4 | 6,718 tok |
| jmagar/swag-mcp SWAG reverse proxy configuration management via MCP. Create, edit, view, and manage nginx | 5 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 2,374 tok |
| thiagolmoraes/leash Sandbox to run AI coding agents (Claude Code, Codex, Gemini, Grok) with full TLS inspectio | 5 | Claude Code | 2 | — |
| 2389-research/fresh-eyes-review 2389-research.github.io Mandatory final sanity check before commits/PRs - catches security vulnerabilities, logic | 5 | Claude Code | 1 | 814 tok |
| rbah31/claude-code-workflow A structured, sprint-based workflow for AI-assisted development with Claude Code. | 5 | Claude Code | 5 | — |
| olanokhin/agent-security-skill Native Claude Code + Codex skills for AI security review. Also ships instruction files for | 5 | Codex, OpenCode | 1 | 140 tok |
| zebbern/termstack An open-source agentic vibe coding platform that helps you build your own platform (Claude | 5 | Claude Code, GitHub Copilot | 12 | 15,538 tok |
| ashp15205/scankii A local-first SAST & Runtime Security scanner built exclusively for LLM Agents. Detects cr | 5 | Cursor | 1 | 123 tok |
| NFTYoginis/agency-of-one nftyoginis.github.io A Claude Code template for running a content/design business as a solo operator. One orche | 5 | Claude Code | 4 | 1,973 tok |
| yunsii/wezdeck A flight deck for your AI agents — multi-agent terminal platform built on WezTerm + tmux + | 5 | Claude Code, Codex, OpenCode | 4 | 4,379 tok |
| trongnguyenbinh/zalo-bot-mcp MCP channel server for the Zalo Bot API. Talk to your Claude Code session from Zalo, with | 5 | Claude Code | 8 | — |
| MangroveTechnologies/mangrove-agent mangrovedeveloper.ai Claude agent for use with the Mangrove Developer API & MCP Server. | 5 | Claude Code | 5 | 874 tok |
| Sandeeprdy1729/timps timps-website.vercel.app The AI memory layer with 17 intelligence tools — catches contradictions, predicts burnout, | 5 | Claude Code, Codex, OpenCode | 2 | 24,407 tok |
| xChechi/xche-ai-app-security-pack stefannasev.dev Free security guardrails for apps built with AI coding tools (Claude Code, Cursor, Lovable | 5 | Claude Code, Codex, OpenCode | 2 | 1,527 tok |
| TyrusRC/praetor Agentic pentest & red-team harness via Burp Suite MCP toolkit | 5 | Claude Code, Codex, OpenCode | 2 | 8,151 tok |
| danygiguere/audit-skills Language- and framework-agnostic audit checklists for AI coding agents — security, correct | 5 | Claude Code, Codex, OpenCode | 2 | 2,553 tok |
| TheSethRose/Vulnerability-Scanning sethrose.dev Local-first vulnerability and supply-chain scanning for agent runtimes. | 5 | Codex, OpenCode | 1 | 978 tok |
| zebbern/pocmap zebbern.github.io MCP-native CVE, PoC & exploit discovery toolkit (Metasploit, Nuclei, GitHub & more) | 5 | Claude Code, Codex, OpenCode | 2 | 4,679 tok |
| badarosama/mcp-control-plane Policy-based authorization middleware for MCP servers. Role-based tool filtering, call enf | 5 | Claude Code | 1 | 30 tok |
| sv-tools/scrypted-mcp-plugin Scrypted plugin that exposes a Streamable HTTP Model Context Protocol endpoint, with OAuth | 5 | Claude Code | 1 | 3,499 tok |
| jiezeng2004-design/PatchWarden patchwarden-showcase-redesign.yistart.chatgpt.site Turn your ChatGPT conversations into safe, auditable local execution. PatchWarden lets you | 5 | Codex, OpenCode | 1 | 539 tok |
| mappedsky/seizu mappedsky.github.io A neo4j dashboard and reporting tool. | 5 | Claude Code | 1 | 6 tok |
| HanZephyr/AI-Data-Access-Gateway An open-source secure data access gateway for AI agents. It provides database safety acces | 5 | Codex, OpenCode | 1 | 372 tok |
| ayuksel-tenb/tenable-attack-mapper MCP server that maps Tenable Security Center findings to the MITRE ATT&CK framework, then | 5 | Claude Code | 1 | — |
| zessu/samson-ai Your personal fitness trainer. Get fitness recommendations daily through email/SMS | 5 | Codex, OpenCode | 1 | 1,449 tok |
| Nikita3005/taintgate Provenance-aware runtime security for AI agents with deterministic ALLOW / REVIEW / BLOCK | 5 | Codex, OpenCode | 1 | 259 tok |
| comisai/comis comis.ai Open-source security-first runtime for AI agents that learn and act across sessions. | 5 | Claude Code, Codex, OpenCode | 2 | 20,957 tok |
| BlockSecCA/joern-mcp MCP server wrapping Joern for AI-driven code security analysis | 5 | Claude Code | 2 | 347 tok |
| velias/mcp-auth-adapter An authentication adapter for Model Context Protocol (MCP) world. It sits in front of any | 5 | Codex, OpenCode | 1 | 5,980 tok |
| Mun1to/vidorq Open-source AI video editor built on DaVinci Resolve Free. Describe the edit, train it wit | 5 | Claude Code | 1 | — |
| agent-receipts/openclaw obsigna.dev Agent Receipts / Obsigna plugin for OpenClaw — cryptographically signed audit trail for ag | 5 | Claude Code, Codex, GitHub Copilot, OpenCode | 6 | 1,940 tok |
| meltforce/vimmary vimmary.meltforce.org YouTube video summary service. Karakeep webhook → transcript → LLM summary → semantic sear | 5 | Claude Code | 2 | 6,730 tok |
| samonti86/jarvis Always-on Windows voice assistant with a 36-tool agentic layer (Claude). Local wake word + | 5 | Claude Code | 1 | 9,033 tok |
| zakariaf/SecScanMCP Comprehensive security scanner for MCP (Model Context Protocol) servers. 12+ analyzers, | 5 | Claude Code | 1 | 4,392 tok |
| nette/mcp-inspector ai.nette.org Nette application inspector via MCP protocol | 5 | Codex, OpenCode | 1 | 1,474 tok |
| miounet11/scagent 🔍 ShenCha - AI Code Audit Agent | Security Scanner, Vulnerability Detection, Performance | 5 | Claude Code | 1 | 774 tok |
| agentic-threat-modeling/MAESTRO agentic-threat-modeling.github.io OWASP MAESTRO Threat Modeling Playbook | 5 | Claude Code | 1 | 4,581 tok |
| avvocati-e-mac/AnonyMCP Server MCP locale che pseudonimizza documenti legali italiani prima di esporli a un LLM (p | 5 | Claude Code, Codex, OpenCode | 4 | 6,194 tok |