2,004 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,510Claude Code6,601Data and AI3,691Backend and APIs3,489Languages3,402Planning3,208Git and workflow3,142Code review2,734Memory and context2,361Testing2,349DevOps and cloud2,296Research2,292
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| raccioly/websec-validator pypi.org Local-first security recon that briefs your AI coding agent: facts + tailored probes, code | 2 | Codex, OpenCode | 1 | 1,540 tok |
| WZ/agent-gate Single-user audit gate for AI agents that talk HTTP — local proxy + dashboard, no backend, | 2 | Claude Code | 1 | 4,691 tok |
| lodetomasi/claude-code-training-lab Training lab con 15 bug intenzionali per imparare Claude Code. 11 moduli pratici: dall'esp | 2 | Claude Code | 8 | — |
| NexusOne23/noid-privacy-workstation noid-privacy.com 🛡️ Fully-hardened Security & Privacy OS based on Fedora 44 + GNOME · for Dev, Admin, Crea | 2 | Codex, OpenCode | 1 | 4,512 tok |
| drsh4dow/bevy-agent-feedback-plugin Let AI coding agents (Claude, Codex, Pi) see and control your Bevy game - remote input inj | 2 | Codex, OpenCode | 1 | 177 tok |
| lopes/foxglove Automatically generate decoy files. | 2 | Claude Code | 1 | 1,750 tok |
| php-workx/fuse A local firewall for AI agent commands | 2 | Claude Code, Codex, OpenCode | 2 | 2,996 tok |
| kounetsuman/zashiki Zashiki is an orchestration cockpit for visualizing Claude Code sessions on a single scree | 2 | Claude Code | 3 | 1,280 tok |
| hackingyseguridad/IA hackingyseguridad.com IA aplicada a la detección de vulnerabilidades y hacking (Offensive AI) | 2 | Claude Code | 14 | 1,751 tok |
| Mikacr1138/claude-bug-bounty Enable efficient bug bounty hunting across Web2 and Web3 with a tool that supports full re | 2 | Claude Code | 1 | 761 tok |
| YankielDBC2/saas-cybersecurity Provider-aware Agent Skill for evidence-based SaaS security audits and regression-safe har | 2 | Codex, OpenCode | 1 | 335 tok |
| kirti/claude-power-modes A reusable library of named prompt "modes" (SECURITYMODE, STAFFENGINEER, TESTMODE, etc.) f | 2 | Claude Code, GitHub Copilot | 2 | 1,417 tok |
| pashki975/thm-claude-kit A coach for TryHackMe, powered by Claude Code. A consistent methodology (classify → enumer | 2 | Claude Code | 1 | 337 tok |
| charliechenye/SkillGate chenyezhu.com Pre-merge and pre-install trust checks for AI-agent skills and MCP configurations. Scan ca | 2 | Codex, OpenCode | 1 | 477 tok |
| uttej-badwane/secure-cloud-prompt-engineering Security-focused prompt library and Claude Code skill for automated IaC security reviews. | 2 | Claude Code | 1 | 878 tok |
| DjFikie25/shipkit Build full-stack Next.js and React Native apps with integrated auth, database, AI chat, an | 2 | Codex, OpenCode | 1 | 3,842 tok |
| Fodhol/skills fodhol.github.io 🚀 Enhance your AI-assisted security workflows with plugins from the Trail of Bits Skills | 2 | Claude Code | 1 | 1,781 tok |
| vinayaklatthe/microsoft-security-agent-toolkit Action layer for Microsoft Security AI agents - MCP servers, KQL snippets, Logic Apps temp | 2 | Claude Code, GitHub Copilot, Cursor | 3 | 1,694 tok |
| yu-iskw/skill-inspector npmjs.com A sophisticated tool designed to bring quality and security to the world of AI Agent Skill | 2 | Claude Code, Codex, OpenCode | 2 | 617 tok |
| mirekondro/The-Pre-Flight-Check mirekondro.github.io ✈️ Stop your AI coding agent from declaring 'done' on broken code. Fail-fast quality gate: | 2 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 3,486 tok |
| cubxxw/agent-kit Public, versioned Agent Skills to safely bootstrap and sync Claude Code, Codex, Qwen Code, | 2 | Claude Code, Codex, OpenCode | 4 | 188 tok |
| rodrigopg/whatsapp-mcp WhatsApp MCP Server — community fork with LID contact fixes, group management, security ha | 2 | Claude Code, Codex, OpenCode | 2 | 865 tok |
| getskillseal/skillseal getskillseal.github.io Self-verifying agent skills. Your seal of approval. 🦭 | 2 | Claude Code, Codex, OpenCode | 2 | 751 tok |
| morodomi/redteam-skills Claude Code Plugin for automated security auditing. Static analysis + dynamic verification | 2 | Claude Code | 1 | 1,849 tok |
| AbhiiGatty/cld-flare-maxxing cld-flare-maxxing.abhiigatty.com Claude Code and Codex plugin that audits, explains, and safely changes Cloudflare. Read-on | 2 | Claude Code, Codex, GitHub Copilot, OpenCode | 12 | 3,719 tok |
| filthyrake/damens_mcps A collection of MCP servers I've put together with various AI tools for infrastructure man | 2 | Claude Code, GitHub Copilot | 6 | 14,328 tok |
| v0idw4lker/trustmcp Free, open-source security scanner for MCP servers, static analysis, live dynamic probing | 2 | Claude Code | 2 | 141 tok |
| vaquarkhan/kafka-mcp-enterprise-server vaquarkhan.github.io A production-ready Model Context Protocol (MCP) server for Apache Kafka. Features Informat | 2 | Codex, GitHub Copilot, Cursor, OpenCode | 5 | 1,155 tok |
| willow-memory/willow-mcp Agent-neutral MCP server with persistent memory (SOIL + Postgres KB) and a sandboxed task | 2 | Claude Code | 4 | — |
| hexxla/mcp-ratchet Go package for enforcing tool call order in MCP servers. Token-based dependency system wit | 2 | Claude Code, Codex, OpenCode, Windsurf | 17 | 1,910 tok |
| salingnh/android-reverse-engineering-mcp Claude Code skill to support Android app's reverse engineering. (Safe) | 2 | Codex, OpenCode | 1 | 1,089 tok |
| bluenexus-ai/gemini-cli-extension app.bluenexus.ai Connect Gemini CLI to your BlueNexus Universal MCP: one OAuth sign-in, 200+ data sources, | 2 | Gemini CLI | 1 | 285 tok |
| kenithphilip/Tessera Signed provenance labels and taint-tracking policy for LLM agent security. The core librar | 2 | Claude Code | 1 | 3,345 tok |
| waleedkhanbaloch/claude-code-safety-net waleedkhanbaloch.github.io 🛡️ Enhance code safety with Claude Code Safety Net, a tool designed to identify and mitig | 2 | Claude Code, Codex, OpenCode | 2 | 3,226 tok |
| Taibur-Rahaman/Agent2Wp-AI-WordPress-Agent Security engine for WordPress AI Abilities — fail-closed risk classification, permission g | 2 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 714 tok |
| akar5h/jakk Black-box security scanner for MCP servers — deterministic single-call probes, no LLM. 13 | 2 | Claude Code | 1 | 668 tok |
| kummahiih/secure-claude A hardened, containerized environment for running Claude Code as an AI agent with access t | 2 | Claude Code | 1 | 261 tok |
| rashidazarang/email-intel Email infrastructure fingerprinting for macOS | 2 | Claude Code, Codex, OpenCode | 2 | 619 tok |
| babywyrm/mcpnuke MCP red teaming & security scanner — enumerate, probe, and exploit Model Context Protocol | 2 | Codex, Cursor, OpenCode | 6 | 1,087 tok |
| aki0225/AgentToolGate A local AI Agent tool governance gateway: it does not prevent prompt injection, but preven | 2 | Claude Code, Codex, OpenCode | 2 | 807 tok |
| ArcadeAI/arcade-mcp-ts TypeScript framework for building MCP servers with built-in OAuth (21 providers), secret i | 2 | Claude Code | 1 | 1,246 tok |
| ArisRhiannon/vibecheck arisrhiannon.github.io Offline, no-AI "safe to ship?" gate for vibe-coded apps — finds the security mistakes AI c | 2 | Codex, OpenCode | 1 | 490 tok |
| decoy-run/decoy-redteam npmjs.com Autonomous red team for MCP servers. Sends adversarial payloads to your tools, proves expl | 2 | Codex, OpenCode | 1 | 1,499 tok |
| ns408/agentic-lab A lab exploring agentic AI for Cloud and DevOps, built as small, runnable demos. Work in p | 2 | Claude Code | 2 | — |
| gordcurrie/unifi-mcp MCP server written in Go that exposes UniFi home-network operations as tools | 2 | Claude Code, Codex, GitHub Copilot, OpenCode | 4 | 2,346 tok |
| Coding-Dev-Tools/envault coding-dev-tools.github.io Sync, rotate, and manage .env files across environments securely | 2 | Codex, OpenCode | 1 | 584 tok |
| sdfdu/evopilot Local-first workflow compiler that turns repeated AI-agent work into evidence-backed, qual | 2 | Codex, OpenCode | 1 | 97 tok |
| 3z/hacktricks-mcp Fast, self-hostable MCP server giving AI agents token-authenticated full-text search over | 2 | Codex, OpenCode | 1 | 778 tok |
| ImBIOS/belifoa ⚡ High-performance, compact Linear client & MCP server for AI agents. Reduces prompt conte | 2 | Codex, OpenCode | 1 | 1,640 tok |
| adudley78/mcp-audit Security scanner for MCP (Model Context Protocol) server configurations. Detects prompt in | 2 | Claude Code | 1 | 22,658 tok |