1,980 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,374Claude Code6,573Data and AI3,706Backend and APIs3,486Languages3,398Planning3,181Git and workflow3,100Code review2,701Memory and context2,354Testing2,311Research2,292DevOps and cloud2,282
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| pashov/skills Pashov Audit Group Skills | 1,124 | Claude Code | 1 | 116 tok |
| vndee/llm-sandbox vndee.github.io Lightweight and portable LLM sandbox runtime (code interpreter) Python library. | 1,119 | Claude Code, GitHub Copilot | 2 | 4,844 tok |
| mrwadams/stride-gpt stridegpt.streamlit.app An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat m | 1,112 | Codex, OpenCode | 1 | 4,122 tok |
| agentlas-ai/Agentlas-OS agentlas.cloud Agent OS: keep specialist agents in a hub, spin up a temporary orchestrator per task. Loca | 1,103 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 7,327 tok |
| prompt-security/clawsec prompt.security A complete security skill suite for OpenClaw, Hermes, PicoClaw and NanoClaw agents (and va | 1,100 | Claude Code, Codex, OpenCode | 2 | 3,541 tok |
| TencentCloudBase/CloudBase-AI-Toolkit docs.cloudbase.net Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & | 1,094 | Claude Code, Codex, OpenCode | 2 | 6,543 tok |
| google/mantis cloud.google.com A modular, stack-agnostic toolkit of security review skills for AI coding agents to autono | 1,030 | Codex, OpenCode | 1 | 670 tok |
| SafeAI-Lab-X/ClawKeeper ClawKeeper: Comprehensive Safety Protection for OpenClaw Agents Through Skills, Plugins, a | 1,023 | GitHub Copilot | 1 | 574 tok |
| DataDog/pup datadoghq.com Give your AI agent a Pup — a CLI companion with 200+ commands across 33+ Datadog products. | 1,001 | Claude Code, Codex, OpenCode | 2 | 1,841 tok |
| Pantheon-Security/medusa pantheonsecurity.io AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ | 979 | Claude Code | 1 | 2,806 tok |
| trailofbits/claude-code-devcontainer Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security a | 936 | Claude Code | 1 | — |
| SylphxAI/pdf-reader-mcp sylphxai.github.io Give your AI agent eyes for PDFs — structured text, tables, OCR, visual evidence, and page | 917 | Codex, OpenCode | 19 | 690 tok |
| agentic-community/mcp-gateway-registry agentic-community.github.io Enterprise-ready MCP Gateway & Registry that centralizes AI development tools with secure | 898 | Claude Code | 1 | 15,542 tok |
| pocketpaw/pocketpaw pocketpaw.xyz Your AI agent in 30 seconds. Not 30 hours. Self-hosted, open-source personal AI with deskt | 878 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 6,715 tok |
| Skyvern-AI/rustwright Playwright's API on a Rust CDP engine — Chromium browser automation for Python & Node, no | 875 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 996 tok |
| agentscope-ai/agentscope-runtime runtime.agentscope.io A production-ready runtime framework for agent apps with secure tool sandboxing, Agent-as- | 863 | GitHub Copilot | 1 | 646 tok |
| TalEliyahu/Awesome-AI-Security awesomeaisecurity.com Curated resources, research, and tools for securing AI systems | 862 | Codex, OpenCode | 1 | 759 tok |
| jdevalk/specification.website specification.website Website specification — HTML, accessibility, security, SEO, agent-readiness. Platform-agno | 848 | Claude Code | 1 | 7,526 tok |
| luckyPipewrench/pipelock pipelab.org Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, | 835 | Claude Code, Codex, OpenCode | 2 | 2,750 tok |
| cyberkaida/reverse-engineering-assistant MCP server for reverse engineering tasks in Ghidra 👩💻 | 823 | Claude Code, Codex, GitHub Copilot, OpenCode | 7 | 4,764 tok |
| google/sam sam-mesh.dev SAM Sovereign Agent Mesh | 822 | Codex, OpenCode | 1 | 1,068 tok |
| H-mmer/pentest-agents Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and | 817 | Claude Code, Codex, GitHub Copilot, OpenCode | 17 | 63,845 tok |
| ThinkWatchProject/ThinkWatch thinkwat.ch Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, | 813 | Claude Code | 1 | 1,011 tok |
| cloudflare/mcp mcp.cloudflare.com MCP server for the Cloudflare API | 812 | Claude Code, Codex, OpenCode | 2 | 3,212 tok |
| irsdl/webhacklist irsdl.github.io Archive of the Top 10 Web Hacking Techniques - every nominee since 2006, preserved | 809 | Claude Code, Codex | 15 | 1,363 tok |
| hoophq/hoop hoop.dev One gateway in front of every protocol. Same policy across MCP, LLMs, databases and contai | 808 | Claude Code | 5 | 7,260 tok |
| gemini-cli-extensions/security Google's Security extension for the Gemini CLI that finds vulnerabilities in your code cha | 791 | Gemini CLI | 1 | 3,993 tok |
| apify/mcpc npmjs.com A universal CLI client for MCP. mcpc supports persistent sessions, stdio/HTTP, OAuth 2.1, | 768 | Claude Code | 1 | 12,679 tok |
| FrancescoStabile/numasec The AI Agent for Cyber Security. | 754 | Codex, OpenCode | 1 | 2,610 tok |
| sgasser/pasteguard pasteguard.com AI gets the context. Not your private data. Local-first privacy proxy for browser chat, AI | 741 | Claude Code, Codex, OpenCode | 2 | 461 tok |
| hadriansecurity/OpenHack Lightweight, file-based workspace for source-guided whitebox security review. | 738 | Codex, OpenCode | 1 | 2,001 tok |
| ZeroLeaks/zeroleaks zeroleaks.ai AI Security Scanner - Test your AI systems for prompt injection and extraction vulnerabili | 732 | Codex, OpenCode | 1 | 2,649 tok |
| Kymo-MCP/mcpcan mcpcan.com MCPCAN is a centralized management platform for MCP services. It deploys each MCP service | 727 | Cursor | 1 | 239 tok |
| borghei/Claude-Skills borghei.github.io 368 AI skills, 76 expert agents, and 859 stdlib Python tools for every team: engineering, | 717 | Claude Code, Codex, GitHub Copilot, Cursor, Gemini CLI, OpenCode | 8 | 9,493 tok |
| solokeys/solo2 solo2.dev Solo 2 firmware in Rust | 708 | Codex, OpenCode | 1 | 1,317 tok |
| arklexai/Agent-First-Organization arklex.ai The official Python library for Arklex framework | 699 | Claude Code | 8 | 633 tok |
| pdovhomilja/nextcrm-app demo.nextcrm.io NextCRM — Open-source CRM built with Next.js 16, React 19, PostgreSQL, Prisma 7, and shadc | 690 | Codex, OpenCode | 1 | 1,428 tok |
| msrbuilds/elementor-mcp emcptools.com WordPress plugin that turns Elementor & WordPress into an MCP server. 200+ AI-ready tools | 683 | Claude Code | 3 | 31,890 tok |
| arcjet/arcjet-js arcjet.com Runtime security for AI apps and agents: prompt injection detection, tool-call authorizati | 682 | Codex, OpenCode | 1 | 452 tok |
| duriantaco/skylos skylos.dev Open source local-first PR scanner that finds dead code, security bugs, secrets, quality r | 671 | Claude Code, Codex, OpenCode | 4 | 1,138 tok |
| vz-risk/VCDB VERIS Community Database | 670 | Claude Code | 2 | 1,089 tok |
| Zyrexnn/Cybermes Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes | 668 | Codex, Cursor, OpenCode | 2 | 2,021 tok |
| paradigmxyz/iron-proxy docs.iron.sh An egress firewall for untrusted workloads. | 660 | Codex, OpenCode | 1 | 1,429 tok |
| s0ld13rr/pentestcode PentestCode - Multi-agent AI penetration testing system with persistent engagement state, | 655 | Claude Code, Codex, OpenCode | 2 | 11,646 tok |
| emiliaprotocol/emilia-protocol emiliaprotocol.ai Authority control plane for autonomous work. EMILIA Gate enforces finite customer-owned ma | 649 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 1,680 tok |
| SonarSource/sonarqube-mcp-server sonarsource.com Official SonarQube MCP Server for code quality and security in AI agents | 637 | Codex, OpenCode | 1 | 2,801 tok |
| apache/casbin-gateway caswaf.org Casbin AI & MCP security gateway for HTTP, online demo: https://door.caswaf.com | 620 | Claude Code, Codex | 1 | 134 tok |
| alibaba/anolisa agentic-os.sh ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with | 619 | Codex, OpenCode | 1 | 5,082 tok |
| provos/ironcurtain ironcurtain.dev A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*htt | 602 | Claude Code, GitHub Copilot, Gemini CLI | 10 | 9,002 tok |
| emersonfelipesp/netbox-proxbox emersonfelipesp.com Netbox Plugin for integration between Proxmox and Netbox | 593 | Claude Code, Codex, OpenCode | 2 | 45,745 tok |