2,004 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,510Claude Code6,601Data and AI3,691Backend and APIs3,489Languages3,402Planning3,208Git and workflow3,142Code review2,734Memory and context2,361Testing2,349DevOps and cloud2,296Research2,292
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| runvouch/runvouch runvouch.com Dead man's switch, cost cap and outcome check for unattended AI agents (Claude Code, OpenC | 0 | Claude Code | 1 | 2,013 tok |
| scanmalware/mcp-server MCP server for the ScanMalware.com API | 0 | Codex, OpenCode | 1 | 1,550 tok |
| jasonpalmer1/wafergraph-mcp wafergraph.com Read-only remote MCP server for wafergraph.com's semiconductor and AI supply-chain dataset | 0 | Claude Code | 1 | 2,406 tok |
| palisadeemail/palisade-mcp palisade.email Local stdio bridge to the Palisade MCP server (SPF, DKIM, DMARC, MTA-STS, BIMI). | 0 | Codex, OpenCode | 1 | 755 tok |
| Bigred97/ato-mcp pypi.org Query the Australian Taxation Office in plain English from Claude or any MCP client. Perso | 0 | Claude Code | 4 | 1,785 tok |
| Atharva-Jayappa/blast-scope A consequence engine for shell commands | 0 | Claude Code | 1 | 2,075 tok |
| BackBond/agent-scan backbond.ai Vet MCP and AI-agent tools before attachment. Local, deterministic static scanning with no | 0 | Codex, OpenCode | 1 | 825 tok |
| CSOAI-ORG/agent-audit-logger-mcp Hash-chained HMAC-signed audit log MCP for A2A (agent-to-agent) calls. Every tool-call, ag | 0 | Cursor | 1 | 181 tok |
| CSOAI-ORG/agent-policy-enforcement-mcp Per-agent-pair IAM for A2A. Define policies ('orchestrator may call billing only when amou | 0 | Cursor | 1 | 163 tok |
| CSOAI-ORG/ai-bom-mcp meok.ai AI Bill of Materials MCP in CycloneDX + SPDX format. Required by EU AI Act Article 11. MIT | 0 | Cursor | 1 | 164 tok |
| CSOAI-ORG/ai-incident-reporting-mcp meok.ai Multi-regime AI incident classification + reporting MCP (EU AI Act Art 73, DORA, NIS2, GDP | 0 | Cursor | 1 | 156 tok |
| CSOAI-ORG/ai-self-audit-mcp meok.ai AI self-audit MCP — AI agents audit their own EU AI Act compliance in real time with signe | 0 | Cursor | 1 | 84 tok |
| CSOAI-ORG/cisa-kev-mcp meok.ai CISA Known Exploited Vulnerabilities MCP. BOD 22-01 + EPSS overlay. MIT | 0 | Cursor | 1 | 194 tok |
| CSOAI-ORG/code-reviewer-ai-mcp meok.ai Code Reviewer MCP — automation tooling for code reviewer. MIT. | 0 | Cursor | 1 | 79 tok |
| CSOAI-ORG/cra-compliance-mcp meok.ai EU Cyber Resilience Act (Reg 2024/2847) → AI governance. CE marking + SBOM. Part of the CS | 0 | Cursor | 1 | 187 tok |
| CSOAI-ORG/cybersecurity-ai-mcp meok.ai cybersecurity-ai-mcp MCP — AI-powered automation tool. MIT. | 0 | Cursor | 1 | 75 tok |
| CSOAI-ORG/dataprivacy-ai-mcp meok.ai dataprivacy-ai-mcp MCP — AI-powered automation tool. MIT. | 0 | Cursor | 1 | 93 tok |
| CSOAI-ORG/deepfake-detector-mcp Analyze images, videos, and audio for deepfake manipulation artifacts. Checks metadata, pr | 0 | Cursor | 1 | 86 tok |
| CSOAI-ORG/dependency-updater-ai-mcp meok.ai Dependency Updater MCP — automation tooling for dependency updater. MIT. | 0 | Cursor | 1 | 78 tok |
| CSOAI-ORG/dora-nis2-crosswalk-mcp meok.ai 🔌 Exposes DORA × NIS2 crosswalk over MCP — for entities in scope for both regimes. 65% ob | 0 | Cursor | 1 | 199 tok |
| CSOAI-ORG/healthcare-ai-governance-mcp MEOK AI Labs — Healthcare AI Governance. FDA SaMD classification, HIPAA compliance, WHO he | 0 | Cursor | 1 | 92 tok |
| CSOAI-ORG/jwt-ai-mcp meok.ai MEOK AI Labs — JWT token operations — decode, validate, generate, inspect. | 0 | Cursor | 1 | 74 tok |
| CSOAI-ORG/mitre-atlas-mcp meok.ai MITRE ATLAS (adversarial AI) threat landscape MCP. MIT | 0 | Cursor | 1 | 187 tok |
| CSOAI-ORG/nis2-compliance-mcp meok.ai NIS2 (Directive EU 2022/2555) Article 21+23 compliance MCP. Entity classification, 10 meas | 0 | Cursor | 1 | 199 tok |
| CSOAI-ORG/nist-rmf-ai-mcp NIST AI Risk Management Framework MCP — MAP, MEASURE, MANAGE, GOVERN functions, risk regis | 0 | Cursor | 1 | 97 tok |
| CSOAI-ORG/otp-ai-mcp meok.ai MEOK AI Labs — Generate and verify TOTP/HOTP codes. | 0 | Cursor | 1 | 70 tok |
| CSOAI-ORG/password-ai-mcp meok.ai Password manager MCP — generate, strength-check, breach monitoring, entropy calculation. Z | 0 | Cursor | 1 | 69 tok |
| CSOAI-ORG/pci-dss-mcp PCI DSS 4.0 payment card compliance MCP server — 12 requirements assessment, cardholder da | 0 | Cursor | 1 | 84 tok |
| CSOAI-ORG/risk-assessment-ai-mcp meok.ai AI risk assessment MCP — NIST AI RMF-aligned risk register with scoring, treatments, contr | 0 | Cursor | 1 | 85 tok |
| CSOAI-ORG/scam-detector-mcp By [MEOK AI Labs](https://meok.ai) | The only MCP server for scam and fraud detection. | 0 | Cursor | 1 | 76 tok |
| CSOAI-ORG/soc2-compliance-ai-mcp meok.ai SOC 2 Type II compliance MCP — Trust Service Criteria audit, access review, change managem | 0 | Cursor | 1 | 93 tok |
| CallMarcus/security-scorecard-mcp Talk to the SecurityScorecard API in natural language from Claude and other MCP clients. C | 0 | Claude Code | 1 | 2,275 tok |
| CSOAI-ORG/security-scanner-ai-mcp meok.ai Security scanning MCP — vulnerability assessment, SAST, DAST, dependency checking, SBOM an | 0 | Cursor | 1 | 85 tok |
| DrBaher/sign-cli cli.drbaher.com Agent-first e-signature CLI. Fully-offline PAdES signer (PKCS#7) — no signup — or hosted p | 0 | Codex, OpenCode | 1 | 1,179 tok |
| Nano-Nimbus/locus | 0 | Claude Code, GitHub Copilot | 7 | 2,120 tok |
| Edu963/ocultar An enterprise-grade Zero-Egress AI Gateway and PII Redaction Engine. Securely sanitizes se | 0 | Claude Code | 3 | 2,935 tok |
| WYRE-AI/blumira-mcp conduit.wyre.ai MCP server for Blumira SIEM integration | 0 | GitHub Copilot | 1 | 292 tok |
| WYRE-AI/freshdesk-mcp MCP server for Freshdesk — tickets, contacts, companies, agents, groups, knowledge base, S | 0 | GitHub Copilot | 1 | 554 tok |
| WYRE-AI/liongard-mcp conduit.wyre.ai MCP server for Liongard — inspector data, environment metrics, and configuration detection | 0 | GitHub Copilot | 1 | 858 tok |
| antonillos/safeselect antonillos.github.io Read-only PostgreSQL & MongoDB access for coding agents. Local, fail-closed MCP enforcemen | 0 | Codex, OpenCode | 1 | 723 tok |
| bch1212/agentvault agentvault-api-production.up.railway.app AI-native credential vault for autonomous agents — Fernet-encrypted API keys, per-agent av | 0 | Claude Code | 1 | 885 tok |
| brnbtech770/blocktrust blocktrust-mvp.vercel.app | 0 | Claude Code, Cursor | 2 | 7,958 tok |
| cchurctrip/verity-mcp MCP server for Verity skills. bearer-auth proxy | 0 | Claude Code | 1 | 1,279 tok |
| civdotiq/civ.iq civdotiq.org Civic intelligence from government data, organized for public use. Open source. | 0 | Claude Code | 4 | 803 tok |
| cristianmoroaica/bountyverdict cristianmoroaica.github.io Seven x402 decision APIs and installable agent skills for GitHub bounties, CI, skill secur | 0 | Codex, OpenCode | 1 | 324 tok |
| davidmosiah/delx-agent-utilities ontology.delx.ai Open-source stateless utility tools for AI agents: URL, DNS, TLS, OpenAPI, x402, JWT, CSV/ | 0 | Codex, OpenCode | 1 | 248 tok |
| dir-ai/repotector ⬡ The repo guardian AI agents handshake with before they touch your code. Handshake-first | 0 | Claude Code, Codex, GitHub Copilot, OpenCode | 4 | 648 tok |
| elberacasa/umbra umbra-badge.umbrabadge.workers.dev The trust score for AI-generated code. One command verifies what your coding agent shipped | 0 | Claude Code, Codex, OpenCode | 1 | 933 tok |
| ertugrulakben/dep-oracle npmjs.com Predictive dependency security engine. Trust Scores for npm/Python packages. Detects zombi | 0 | Claude Code | 1 | 435 tok |
| gopalrajsuresh/covalent-bond npmjs.com Peer-to-peer, end-to-end-encrypted collaboration channel for AI coding agents over MCP. Th | 0 | Claude Code | 4 | — |