1,998 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,489Claude Code6,592Data and AI3,693Backend and APIs3,493Languages3,401Planning3,203Git and workflow3,138Code review2,732Memory and context2,360Testing2,339DevOps and cloud2,295Research2,291
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| nav33n25/IMCP Welcome to IMCP – a deliberately vulnerable framework that exposes 14 critical security we | 4 | GitHub Copilot | 1 | 286 tok |
| toyamagu-2021/argocd-mcp-server ArgoCD MCP Server | 4 | Claude Code | 2 | 1,795 tok |
| jaskaranhundal/usap-skills usap-security.vercel.app Open-source AI cybersecurity agent skills for SOC, incident response, threat hunting, red | 4 | Claude Code, Gemini CLI | 2 | 2,781 tok |
| beriktassuly/solana-audit-skill Evidence-backed Solana audit skill for Claude Code and Agent Skills: report-backed taxonom | 4 | Codex, OpenCode | 1 | 279 tok |
| alinotfoundbtw/sounding Governance for agent instructions: audit, score, and pin MCP servers, Agent Skills, and pr | 4 | Claude Code | 1 | 1,750 tok |
| KSEGIT/Version-Sentinel Claude Code plugin that hard-blocks dependency additions, bumps, and downgrades until a fr | 4 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 3,209 tok |
| reuvenaor/israel-statistics-mcp Israel Statistics MCP | 4 | Claude Code | 8 | 1,451 tok |
| lidless-labs/wazuh-mcp lidless.dev Your SIEM answers live behind a console you babysit. wazuh-mcp reads Wazuh alerts, agents, | 4 | Codex, OpenCode | 1 | 1,156 tok |
| thekie/read-no-evil-mcp A secure email gateway MCP server that protects AI agents from prompt injection attacks hi | 4 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 1,233 tok |
| blackfoxxx/Mobix Authorized Android pentest lab, drivable by hand or by AI — Frida bypass chain, live traff | 4 | Claude Code | 1 | — |
| badchars/supply-chain-mcp-server npmjs.com 90-tool MCP server for software supply chain security — OSV, GHSA, NVD, EPSS, CISA KEV, np | 4 | Claude Code | 1 | 550 tok |
| hexproofdev/oring Unprivileged, self-applied Landlock + seccomp confinement wrapper — no root, no daemon, on | 4 | Claude Code | 1 | 1,181 tok |
| xsourabhsharma/ai-security-audit-pro Universal security-audit plugin and CLI engine for AI agents with OWASP-mapped reports for | 4 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 753 tok |
| MilindGaharwar/fettle pypi.org Open-source trust layer for AI coding agents: in-session quality, delegation-safe policy, | 4 | Claude Code, Codex, GitHub Copilot, OpenCode | 18 | 250 tok |
| MMoMM-org/miyo-kado Where AI meets your vault, on your terms... Obsidian Vault MCP Server | 4 | Claude Code, Codex, OpenCode | 3 | 1,884 tok |
| femitfash/copilot-engine Reusable backend for building Claude-powered AI copilots with agentic tool use, SSE stream | 4 | Claude Code | 3 | 1,555 tok |
| 0xSoftBoi/suwappubot suwappu.bot Cross-chain DEX infrastructure for humans and AI agents — swap tokens across 14 chains via | 3 | Claude Code, Codex, OpenCode | 41 | 5,802 tok |
| ali-ulu/huqan huqan.com Local-first verification layer for AI agents: evidence, provenance, policy gates, human ap | 3 | Claude Code, Codex, OpenCode | 2 | 1,022 tok |
| aarifmms/keyblind keyblind.vercel.app keyblind | 3 | Claude Code | 1 | 923 tok |
| vibgrate/cli vibgrate.com Local codebase intelligence for AI coding agents and software teams, in the CLI and VS Cod | 3 | Codex, OpenCode | 1 | 953 tok |
| Mickdownunder/SafeInstall Open-source CLI that blocks risky npm, pnpm, and bun installs before they run. | 3 | Claude Code | 2 | — |
| JinNing6/CyberHuaTuo-Plugin AI Agent Error Doctor: paste MCP / LangChain / CrewAI tracebacks, get root cause, exact fi | 3 | Claude Code, Codex, OpenCode | 4 | 156 tok |
| CSOAI-ORG/iso-27001-ai-mcp MEOK AI Labs MCP Server | 3 | Cursor | 1 | 89 tok |
| getmcpm/cli npmjs.com MCP security guard + package manager. Block prompt injection, tool poisoning and rug-pulls | 3 | Claude Code | 1 | 46,941 tok |
| cunicopia-dev/gmail-mcp Multi-account Gmail MCP server — unified search/read/draft/labels across N Google accounts | 3 | Claude Code | 1 | 3,556 tok |
| soden46/engineer-flow Framework-agnostic AI engineering control plane with project-aware routing, 0–2 specialist | 3 | Codex, OpenCode | 1 | 587 tok |
| densmirnov/hidden-achievements-skill Sealed hidden daily achievements for team agents: anti-spam, prompt-injection safe, no ret | 3 | Codex, OpenCode | 1 | 2,394 tok |
| mishoko/solidity-auditor-pulse x.com A benchmark harness that measures how well Claude Code skills perform at smart-contract se | 3 | Claude Code | 1 | 3,752 tok |
| bokiko/KyZN kyzn.dev Autonomous code improvement CLI powered by Claude Code | 3 | Claude Code | 1 | 2,105 tok |
| chtnnh/know-code kc.chtnnhfoundation.org k(no)w-code - your agents dont push until you know exactly whats changed | 3 | Claude Code, Codex, OpenCode | 3 | 362 tok |
| Calvin-LLC/agentic-hardening-skill Evidence-driven codebase hardening skill. Audits OWASP Top 10:2025, supply chain (SBOM vs | 3 | Codex, OpenCode | 1 | 91 tok |
| matanryngler/deployshield 🛡️ Production safety guardrails for Claude Code and Gemini CLI. Intercepts and blocks dan | 3 | Claude Code | 1 | 903 tok |
| MuhammedZohaib/patchman Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for | 3 | Claude Code, Codex, OpenCode | 2 | 250 tok |
| chris-peterson/ClaudeWatch chris-peterson.github.io bridge.ai/ClaudeWatch: screen dangerous shell commands/scripts | 3 | Claude Code, Codex, OpenCode | 4 | 2,951 tok |
| punt-labs/beadle Claude Code via e-mail based on an addressbook with UNIX style rwx permissions per interac | 3 | Claude Code, Codex, OpenCode | 4 | 2,678 tok |
| Edmonds-Commerce-Limited/claude-code-hooks-daemon Daemon-based hooks system for Claude Code with lazy startup, auto-shutdown, and project-le | 3 | Claude Code | 32 | 13,348 tok |
| Luxvil/ai-coding-rules luxvil.github.io 🤖 Enhance AI coding assistants with battle-tested rules for reliability, predictability, | 3 | Claude Code | 1 | 1,894 tok |
| HendrikReh/llm-guard AI Coding Hackathon Project - Experimenting with AI-assisted development workflows | 3 | Codex, OpenCode | 1 | 3,941 tok |
| Baba01hacker666/gemini-redteam Red team gemini skills and plugins | 3 | Gemini CLI | 1 | 1,071 tok |
| kent-tokyo/shohei Rust MCP server with 168 security tools for Claude — DNS/DNSSEC, TLS, email security, OSIN | 3 | Codex, OpenCode | 1 | 2,537 tok |
| gw0/docker-claude-code Dockerized Claude Code Sandbox | 3 | Claude Code | 1 | 894 tok |
| combinatrix-ai/agenv nvm / pyenv for AI coding agents | 3 | Claude Code | 5 | 290 tok |
| ggoodman/mcp-server-go Golang implementation of the streaming MCP HTTP transport with sessions, auth and horizont | 3 | Codex, OpenCode | 1 | 701 tok |
| kristiyan-velkov/ai-security-rules Security rules and best practices for common applications, focused on real-world threats a | 3 | Claude Code, Cursor | 1 | — |
| onesimplecode/agent-engineering-standards This repo hands your AI coding agent a rulebook and your CI the checks that enforce it, ca | 3 | Codex, OpenCode | 1 | 7,802 tok |
| cloudbees-oss/devops-agent-kit Turn your AI coding assistant into a DevOps-specialized agent using the CloudBees Unify MC | 3 | Claude Code | 2 | 1,522 tok |
| hidetsugu-miya/claude-plugins | 3 | Claude Code, Codex, OpenCode | 6 | 1,318 tok |
| a8cteam51/claude-code-plugins Claude Code plugins by Automattic's Special Projects team for WordPress development, secur | 3 | Claude Code | 1 | 889 tok |
| SecondLifes/delphi-expert An opinionated ecosystem of rules, skills and steerings to elevate Delphi development to s | 3 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 11,182 tok |
| hyperpolymath/boj-server hyperpolymath.github.io One MCP stdio endpoint for a whole toolchain — GitHub, GitLab, cloud, mail, browser and re | 3 | GitHub Copilot | 1 | 510 tok |