1,480 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,374Claude Code6,573Data and AI3,706Backend and APIs3,486Languages3,398Planning3,181Git and workflow3,100Code review2,701Memory and context2,354Testing2,311Research2,292DevOps and cloud2,282
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| arklexai/Agent-First-Organization arklex.ai The official Python library for Arklex framework | 699 | Claude Code | 8 | 633 tok |
| msrbuilds/elementor-mcp emcptools.com WordPress plugin that turns Elementor & WordPress into an MCP server. 200+ AI-ready tools | 683 | Claude Code | 3 | 31,890 tok |
| duriantaco/skylos skylos.dev Open source local-first PR scanner that finds dead code, security bugs, secrets, quality r | 671 | Claude Code, Codex, OpenCode | 4 | 1,138 tok |
| vz-risk/VCDB VERIS Community Database | 670 | Claude Code | 2 | 1,089 tok |
| s0ld13rr/pentestcode PentestCode - Multi-agent AI penetration testing system with persistent engagement state, | 655 | Claude Code, Codex, OpenCode | 2 | 11,646 tok |
| emiliaprotocol/emilia-protocol emiliaprotocol.ai Authority control plane for autonomous work. EMILIA Gate enforces finite customer-owned ma | 649 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 1,680 tok |
| apache/casbin-gateway caswaf.org Casbin AI & MCP security gateway for HTTP, online demo: https://door.caswaf.com | 620 | Claude Code, Codex | 1 | 134 tok |
| provos/ironcurtain ironcurtain.dev A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*htt | 602 | Claude Code, GitHub Copilot, Gemini CLI | 10 | 9,002 tok |
| emersonfelipesp/netbox-proxbox emersonfelipesp.com Netbox Plugin for integration between Proxmox and Netbox | 593 | Claude Code, Codex, OpenCode | 2 | 45,745 tok |
| FradSer/dotclaude dotclaude.frad.me A comprehensive development environment with specialized AI agents for code review, securi | 590 | Claude Code | 2 | 1,129 tok |
| chainloop-dev/chainloop docs.chainloop.dev SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, | 583 | Claude Code | 11 | 3,548 tok |
| KeyValueSoftwareSystems/agent-opfor Open-source adversary emulation for AI agents and MCP servers. | 577 | Claude Code, Codex, OpenCode | 2 | 8,568 tok |
| thunder-id/thunderid thunderid.dev ThunderID is a high-performance, open-source identity stack designed for developers to sec | 574 | Claude Code, Codex, GitHub Copilot, OpenCode | 8 | 1,505 tok |
| yhy0/CHYing-agent zc.tencent.com Tencent Cloud Hackathon - Intelligent Penetration Testing Challenge, First Edition Top 9 | 555 | Claude Code | 1 | — |
| nirholas/XActions xactions.app ⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/G | 512 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 11 | 8,439 tok |
| transilienceai/communitytools transilience.ai Open-source Claude Code skills, agents, and slash commands for AI-powered penetration test | 511 | Claude Code | 2 | 1,060 tok |
| epam/ai-dial-chat chat.dialx.ai A default UI for AI DIAL | 504 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 48 | 4,341 tok |
| MHaggis/Security-Detections-MCP detect.michaelhaag.org MCP to help Defenders Detection Engineer Harder and Smarter | 484 | Claude Code, Cursor | 30 | — |
| disler/claude-code-damage-control | 480 | Claude Code | 5 | 17 tok |
| GoPlusSecurity/agentguard Security guard for AI agents — blocks malicious skills, prevents data leaks, protects secr | 459 | Claude Code | 1 | 319 tok |
| ParetoSecurity/pareto-mac paretosecurity.com Automatically audit your Mac for basic security hygiene. | 454 | Claude Code, Codex, OpenCode | 2 | 2,703 tok |
| OWASP/AISVS The AI Security Verification Standard (AISVS) focuses on providing developers, architects, | 444 | Claude Code, Codex, OpenCode | 2 | 617 tok |
| SponsioLabs/Sponsio sponsio.dev Deterministic safety solutions for probabilistic AI agents | 438 | Claude Code | 1 | 2,228 tok |
| leonvanzyl/agentic-coding-starter-kit | 438 | Claude Code, Codex, OpenCode | 27 | 351 tok |
| pegasi-ai/reins reins.sh Stop AI agents from doing things you didn't ask for. | 408 | Claude Code | 3 | — |
| adithyan-ak/AgentHound agenthound.io Offensive security framework for AI agent infrastructure - recon, credential looting, mode | 402 | Claude Code | 2 | 1,136 tok |
| Masriyan/Claude-Code-CyberSecurity-Skill security-life.org A comprehensive collection of 19 Claude Code Skills for cybersecurity professionals ,cover | 397 | Claude Code | 1 | 1,124 tok |
| potatoqualitee/kbupdate 🛡 KB Viewer, Saver, Installer and Uninstaller | 390 | Claude Code, Codex, GitHub Copilot, OpenCode | 10 | 1,046 tok |
| Agent-Threat-Rule/agent-threat-rules agentthreatrule.org Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents | 383 | Claude Code | 6 | — |
| dogwood-policy/dogwood dogwood-policy.github.io Reference parser and interpreter for the Dogwood policy language | 383 | Claude Code, Codex, OpenCode | 6 | 854 tok |
| canyonroad/agentsh agentsh.org Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit. | 382 | Claude Code, Codex, OpenCode | 2 | 596 tok |
| FlareStarter/flarestarter flarestarter.com A full-stack, edge-native SaaS starter built with TanStack Start + Cloudflare Workers | 377 | Claude Code, Codex, OpenCode | 2 | 772 tok |
| vulnersCom/api vulners.com Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits | 372 | Claude Code, Codex, OpenCode | 2 | 1,497 tok |
| Nebulock-Inc/agentic-threat-hunting-framework ATHF is a framework for agentic threat hunting - building systems that can remember, learn | 368 | Claude Code, Codex, OpenCode | 2 | 7,725 tok |
| alexfazio/plankton Write-time code quality enforcement system for Claude Code. Every file edit triggers autom | 364 | Claude Code | 4 | — |
| secure-agentic-framework/saf-mcp secureagenticframework.org SAF-MCP is a comprehensive security framework for documenting and mitigating threats in th | 361 | Claude Code, Codex | 1 | — |
| hypnguyen1209/offensive-claude Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR | 355 | Claude Code | 1 | 4,127 tok |
| zhuyansen/agent-skills-hub agentskillshub.top Discover and compare open-source Agent Skills, tools & MCP servers — with quality scoring, | 355 | Claude Code | 6 | 2,384 tok |
| AndrewDryga/emisar emisar.dev An MCP that lets AI tools securely connect to your infrastructure, write IaaS code, debug | 354 | Claude Code, Codex, Gemini CLI, OpenCode | 31 | 1,962 tok |
| suzuki-shunsuke/ghtkn A CLI to create short-lived (8 hours) GitHub App User Access Token for secure local develo | 354 | Claude Code, Codex, OpenCode | 2 | 19 tok |
| mapbox/mcp-server Mapbox Model Context Protocol (MCP) server | 353 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 2,525 tok |
| YoshiiRyo1/document-templates-for-aws | 352 | Claude Code | 4 | 1,659 tok |
| zksecurity/zkbugs bugs.zksecurity.xyz Reproduce ZKP vulnerabilities | 345 | Claude Code, Codex, OpenCode | 3 | 997 tok |
| kpolley/redai AI-driven vulnerability discovery and live validation | 341 | Claude Code, Codex, OpenCode | 3 | 890 tok |
| m4xx101/cryptex-oss Open-source LLM red-teaming technique toolkit (162 transforms, 36 mutators, 25 tool surfac | 338 | Claude Code | 1 | 3,329 tok |
| PrismorSec/prismor prismor.dev Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue t | 338 | Claude Code, Codex, OpenCode | 2 | 4,780 tok |
| smart-mcp-proxy/mcpproxy-go mcpproxy.app Supercharge AI Agents, Safely | 336 | Claude Code, Codex, OpenCode | 2 | 4,330 tok |
| cellebrite-labs/ghidra-rpc A Ghidra agentic reverse engineering skill. | 323 | Claude Code, Codex, OpenCode | 2 | 3,863 tok |
| yee-yore/DorkAgent 🤖 LLM-powered agent for automated Google Dorking in bug hunting & pentesting. | 320 | Claude Code | 1 | 1,888 tok |
| badchars/darknet-mcp-server npmjs.com 66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onio | 317 | Claude Code | 1 | 336 tok |