973 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,374Claude Code6,573Data and AI3,706Backend and APIs3,486Languages3,398Planning3,181Git and workflow3,100Code review2,701Memory and context2,354Testing2,311Research2,292DevOps and cloud2,282
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| ex-machina-co/opencode-anthropic-auth | 521 | Codex, OpenCode | 1 | 132 tok |
| nirholas/XActions xactions.app ⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/G | 512 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 11 | 8,439 tok |
| epam/ai-dial-chat chat.dialx.ai A default UI for AI DIAL | 504 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 48 | 4,341 tok |
| deonmenezes/mantishack mantishack.com Mantis Hack | 494 | Codex, OpenCode | 25 | 5,183 tok |
| ndycode/codex-multi-auth npmjs.com Codex CLI multi-account OAuth manager with account switching, health checks, runtime rotat | 478 | Codex, OpenCode | 1 | 2,767 tok |
| ParetoSecurity/pareto-mac paretosecurity.com Automatically audit your Mac for basic security hygiene. | 454 | Claude Code, Codex, OpenCode | 2 | 2,703 tok |
| OWASP/AISVS The AI Security Verification Standard (AISVS) focuses on providing developers, architects, | 444 | Claude Code, Codex, OpenCode | 2 | 617 tok |
| leonvanzyl/agentic-coding-starter-kit | 438 | Claude Code, Codex, OpenCode | 27 | 351 tok |
| matty69v/Bug-Bounty-Agents m-sec.tech AI-Powered Agents for Bub-Bounty Pentesting and Red-Teaming purposes | 411 | Codex, OpenCode | 1 | 1,166 tok |
| openhackai/OpenHack openhack.com Open Source Agentic Security Scanner | 401 | Codex, OpenCode | 1 | 218 tok |
| potatoqualitee/kbupdate 🛡 KB Viewer, Saver, Installer and Uninstaller | 390 | Claude Code, Codex, GitHub Copilot, OpenCode | 10 | 1,046 tok |
| openbkn-ai/bkn-foundry BKN Foundry is the Ontology back-end foundation of OpenBKN. It transforms ontology-driven | 385 | Codex, OpenCode | 1 | 984 tok |
| dogwood-policy/dogwood dogwood-policy.github.io Reference parser and interpreter for the Dogwood policy language | 383 | Claude Code, Codex, OpenCode | 6 | 854 tok |
| canyonroad/agentsh agentsh.org Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit. | 382 | Claude Code, Codex, OpenCode | 2 | 596 tok |
| arnica/depsguard depsguard.com Harden your package manager configs against supply chain attacks. | 381 | Codex, OpenCode | 1 | 2,669 tok |
| FlareStarter/flarestarter flarestarter.com A full-stack, edge-native SaaS starter built with TanStack Start + Cloudflare Workers | 379 | Claude Code, Codex, OpenCode | 2 | 772 tok |
| vulnersCom/api vulners.com Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits | 372 | Claude Code, Codex, OpenCode | 2 | 1,497 tok |
| Nebulock-Inc/agentic-threat-hunting-framework ATHF is a framework for agentic threat hunting - building systems that can remember, learn | 369 | Claude Code, Codex, OpenCode | 2 | 7,725 tok |
| mengjian-github/xiaomo-starter-kit xiaomo.dev 🐈⬛ OpenClaw Chinese AI assistant template | Get your own AI personal assistant in 5 minu | 367 | Codex, OpenCode | 1 | 261 tok |
| suzuki-shunsuke/ghtkn A CLI to create short-lived (8 hours) GitHub App User Access Token for secure local develo | 355 | Claude Code, Codex, OpenCode | 2 | 19 tok |
| AndrewDryga/emisar emisar.dev An MCP that lets AI tools securely connect to your infrastructure, write IaaS code, debug | 354 | Claude Code, Codex, Gemini CLI, OpenCode | 31 | 1,962 tok |
| mapbox/mcp-server Mapbox Model Context Protocol (MCP) server | 353 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 2,525 tok |
| zksecurity/zkbugs bugs.zksecurity.xyz Reproduce ZKP vulnerabilities | 345 | Claude Code, Codex, OpenCode | 3 | 997 tok |
| kpolley/redai AI-driven vulnerability discovery and live validation | 341 | Claude Code, Codex, OpenCode | 3 | 890 tok |
| PrismorSec/prismor prismor.dev Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue t | 339 | Claude Code, Codex, OpenCode | 2 | 4,780 tok |
| smart-mcp-proxy/mcpproxy-go mcpproxy.app Supercharge AI Agents, Safely | 337 | Claude Code, Codex, OpenCode | 2 | 4,330 tok |
| adshao/flounder flounders.xyz Autonomous white-hat security auditor for AI-driven code review, bug bounty research, expl | 331 | Codex, OpenCode | 1 | 6,358 tok |
| cellebrite-labs/ghidra-rpc A Ghidra agentic reverse engineering skill. | 323 | Claude Code, Codex, OpenCode | 2 | 3,863 tok |
| felipegcoutinho/openmonetis openmonetis.com Controle financeiro self-hosted com captura automática de notificações bancárias. Lançamen | 312 | Codex, OpenCode | 1 | 4,004 tok |
| apollographql/apollo-mcp-server apollographql.com Apollo MCP Server | 308 | Claude Code, Codex, OpenCode | 5 | 1,032 tok |
| ucsandman/DashClaw dashclaw.io Remote approvals, policy checks, and execution evidence for unattended AI agents. | 297 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 30 | 10,148 tok |
| semgrep/skills semgrep.dev A collection of skills for AI coding agents from Semgrep | 297 | Claude Code, Codex, OpenCode | 2 | 1,020 tok |
| SeaOf0/dsh-redteam-model Multiple modes built on dsh web for authorized security research by red teams, covering pe | 293 | Codex, OpenCode | 1 | 2,748 tok |
| jakejarvis/domainstack.io domainstack.io 🧰 All-in-one domain name intelligence as a service | 286 | Claude Code, Codex, OpenCode | 2 | 5,046 tok |
| Coff0xc/AutoRedTeam-Orchestrator MCP-native security automation workbench (SDK + CLI + MCP) — authorized testing + static A | 263 | Codex, OpenCode | 1 | 1,693 tok |
| opensearch-project/security opensearch.org 🔐 Secure your cluster with TLS, numerous authentication backends, data masking, audit log | 252 | Codex, OpenCode | 1 | 2,198 tok |
| zapier/sdk docs.zapier.com Agent-readable docs, verified examples, and skill manifest for @zapier/zapier-sdk | 249 | Claude Code, Codex, OpenCode | 2 | 2,403 tok |
| finos/git-proxy git-proxy.finos.org Deploy custom push protections and policies on top of Git | 248 | Claude Code, Codex, GitHub Copilot, OpenCode | 17 | 2,404 tok |
| adcontextprotocol/adcp Docs and reference implementation for the Ad Context Protocol | 242 | Claude Code, Codex, OpenCode | 31 | 218 tok |
| coconut-svsm/svsm COCONUT-SVSM | 239 | Codex, OpenCode | 1 | 4,005 tok |
| lalitgehani/SnackBase snackbase.dev SnackBase is a Python/FastAPI-based BaaS providing auto-generated REST APIs, multi-tenancy | 238 | Claude Code, Codex, OpenCode | 2 | 4,006 tok |
| Hoylon/peerbridge-mcp Local-first, auditable multi-agent control room for coding, review, evidence, and private | 238 | Codex, OpenCode | 1 | 200 tok |
| Sumukh/Ignite newline.co A comprehensive Flask boilerplate to build SaaS applications that includes Stripe billing, | 232 | Codex, OpenCode | 1 | 974 tok |
| grisuno/LazyOwn reddit.com LazyOwn RedTeam/APT Framework is the first RedTeam Framework with an AI-powered C&C, featu | 226 | Claude Code, Codex, OpenCode | 2 | 15,495 tok |
| Cisco-Talos/EvidenceForge Generate realistic synthetic security logs for cybersecurity threat hunting training and r | 225 | Claude Code, Codex, OpenCode | 2 | 10,879 tok |
| sondera-ai/sondera-coding-agent-hooks Hooking implementations and supporting tools for various coding agents (Claude, Cursor, Ge | 223 | Claude Code, Codex, OpenCode | 3 | 1,505 tok |
| vinikjkkj/zapo zapo.to 🧩 Lightweight, high-performance TypeScript library for the WhatsApp Web protocol, built f | 223 | Claude Code, Codex, OpenCode | 2 | 12,947 tok |
| first-fluke/fullstack-starter deepwiki.org Production-ready fullstack monorepo template with Next.js, FastAPI, Flutter, Terraform, an | 222 | Claude Code, Codex, OpenCode | 8 | 3,600 tok |
| kstenerud/yoloai yoloai.dev Your agent is a security risk, so treat it like one. yoloAI does AI agent sandboxing right | 210 | Claude Code, Codex, OpenCode | 5 | 4,163 tok |
| spire-studio/cloakbot A privacy-first AI agent that sanitizes your prompts locally with a local LLM before forwa | 209 | Claude Code, Codex, OpenCode | 2 | 770 tok |