1,980 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,374Claude Code6,573Data and AI3,706Backend and APIs3,486Languages3,398Planning3,181Git and workflow3,100Code review2,701Memory and context2,354Testing2,311Research2,292DevOps and cloud2,282
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| FradSer/dotclaude dotclaude.frad.me A comprehensive development environment with specialized AI agents for code review, securi | 590 | Claude Code | 2 | 1,129 tok |
| chainloop-dev/chainloop docs.chainloop.dev SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, | 583 | Claude Code | 11 | 3,548 tok |
| KeyValueSoftwareSystems/agent-opfor Open-source adversary emulation for AI agents and MCP servers. | 577 | Claude Code, Codex, OpenCode | 2 | 8,568 tok |
| thunder-id/thunderid thunderid.dev ThunderID is a high-performance, open-source identity stack designed for developers to sec | 574 | Claude Code, Codex, GitHub Copilot, OpenCode | 8 | 1,505 tok |
| yhy0/CHYing-agent zc.tencent.com Tencent Cloud Hackathon - Intelligent Penetration Testing Challenge, First Edition Top 9 | 555 | Claude Code | 1 | — |
| faiscadev/fakecloud fakecloud.dev Free, open-source AWS emulator. LocalStack alternative: 105 services, 7,404 operations, tr | 542 | Codex, OpenCode | 1 | 2,606 tok |
| ex-machina-co/opencode-anthropic-auth | 521 | Codex, OpenCode | 1 | 132 tok |
| nirholas/XActions xactions.app ⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/G | 512 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 11 | 8,439 tok |
| transilienceai/communitytools transilience.ai Open-source Claude Code skills, agents, and slash commands for AI-powered penetration test | 511 | Claude Code | 2 | 1,060 tok |
| epam/ai-dial-chat chat.dialx.ai A default UI for AI DIAL | 504 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 48 | 4,341 tok |
| deonmenezes/mantishack mantishack.com Mantis Hack | 494 | Codex, OpenCode | 25 | 5,183 tok |
| MHaggis/Security-Detections-MCP detect.michaelhaag.org MCP to help Defenders Detection Engineer Harder and Smarter | 484 | Claude Code, Cursor | 30 | — |
| disler/claude-code-damage-control | 480 | Claude Code | 5 | 17 tok |
| ndycode/codex-multi-auth npmjs.com Codex CLI multi-account OAuth manager with account switching, health checks, runtime rotat | 478 | Codex, OpenCode | 1 | 2,767 tok |
| OWASP/DockSec owasp.org AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWAS | 477 | Cursor | 1 | 112 tok |
| GoPlusSecurity/agentguard Security guard for AI agents — blocks malicious skills, prevents data leaks, protects secr | 459 | Claude Code | 1 | 319 tok |
| ParetoSecurity/pareto-mac paretosecurity.com Automatically audit your Mac for basic security hygiene. | 454 | Claude Code, Codex, OpenCode | 2 | 2,703 tok |
| OWASP/AISVS The AI Security Verification Standard (AISVS) focuses on providing developers, architects, | 444 | Claude Code, Codex, OpenCode | 2 | 617 tok |
| SponsioLabs/Sponsio sponsio.dev Deterministic safety solutions for probabilistic AI agents | 438 | Claude Code | 1 | 2,228 tok |
| leonvanzyl/agentic-coding-starter-kit | 438 | Claude Code, Codex, OpenCode | 27 | 351 tok |
| matty69v/Bug-Bounty-Agents m-sec.tech AI-Powered Agents for Bub-Bounty Pentesting and Red-Teaming purposes | 411 | Codex, OpenCode | 1 | 1,166 tok |
| pegasi-ai/reins reins.sh Stop AI agents from doing things you didn't ask for. | 408 | Claude Code | 3 | — |
| adithyan-ak/AgentHound agenthound.io Offensive security framework for AI agent infrastructure - recon, credential looting, mode | 408 | Claude Code | 2 | 1,136 tok |
| openhackai/OpenHack openhack.com Open Source Agentic Security Scanner | 401 | Codex, OpenCode | 1 | 218 tok |
| Masriyan/Claude-Code-CyberSecurity-Skill security-life.org A comprehensive collection of 19 Claude Code Skills for cybersecurity professionals ,cover | 399 | Claude Code | 1 | 1,124 tok |
| potatoqualitee/kbupdate 🛡 KB Viewer, Saver, Installer and Uninstaller | 390 | Claude Code, Codex, GitHub Copilot, OpenCode | 10 | 1,046 tok |
| Agent-Threat-Rule/agent-threat-rules agentthreatrule.org Open detection-rule standard for AI agent security threats — like Sigma, but for AI agents | 385 | Claude Code | 6 | — |
| openbkn-ai/bkn-foundry BKN Foundry is the Ontology back-end foundation of OpenBKN. It transforms ontology-driven | 385 | Codex, OpenCode | 1 | 984 tok |
| dogwood-policy/dogwood dogwood-policy.github.io Reference parser and interpreter for the Dogwood policy language | 383 | Claude Code, Codex, OpenCode | 6 | 854 tok |
| canyonroad/agentsh agentsh.org Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit. | 382 | Claude Code, Codex, OpenCode | 2 | 596 tok |
| arnica/depsguard depsguard.com Harden your package manager configs against supply chain attacks. | 381 | Codex, OpenCode | 1 | 2,669 tok |
| FlareStarter/flarestarter flarestarter.com A full-stack, edge-native SaaS starter built with TanStack Start + Cloudflare Workers | 379 | Claude Code, Codex, OpenCode | 2 | 772 tok |
| vulnersCom/api vulners.com Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits | 372 | Claude Code, Codex, OpenCode | 2 | 1,497 tok |
| Nebulock-Inc/agentic-threat-hunting-framework ATHF is a framework for agentic threat hunting - building systems that can remember, learn | 369 | Claude Code, Codex, OpenCode | 2 | 7,725 tok |
| mengjian-github/xiaomo-starter-kit xiaomo.dev 🐈⬛ OpenClaw Chinese AI assistant template | Get your own AI personal assistant in 5 minu | 367 | Codex, OpenCode | 1 | 261 tok |
| alexfazio/plankton Write-time code quality enforcement system for Claude Code. Every file edit triggers autom | 364 | Claude Code | 4 | — |
| secure-agentic-framework/saf-mcp secureagenticframework.org SAF-MCP is a comprehensive security framework for documenting and mitigating threats in th | 361 | Claude Code, Codex | 1 | — |
| hypnguyen1209/offensive-claude Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR | 357 | Claude Code | 1 | 4,127 tok |
| zhuyansen/agent-skills-hub agentskillshub.top Discover and compare open-source Agent Skills, tools & MCP servers — with quality scoring, | 355 | Claude Code | 6 | 2,384 tok |
| suzuki-shunsuke/ghtkn A CLI to create short-lived (8 hours) GitHub App User Access Token for secure local develo | 355 | Claude Code, Codex, OpenCode | 2 | 19 tok |
| AndrewDryga/emisar emisar.dev An MCP that lets AI tools securely connect to your infrastructure, write IaaS code, debug | 354 | Claude Code, Codex, Gemini CLI, OpenCode | 31 | 1,962 tok |
| mapbox/mcp-server Mapbox Model Context Protocol (MCP) server | 353 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 2,525 tok |
| YoshiiRyo1/document-templates-for-aws | 352 | Claude Code | 4 | 1,659 tok |
| zksecurity/zkbugs bugs.zksecurity.xyz Reproduce ZKP vulnerabilities | 345 | Claude Code, Codex, OpenCode | 3 | 997 tok |
| kpolley/redai AI-driven vulnerability discovery and live validation | 341 | Claude Code, Codex, OpenCode | 3 | 890 tok |
| PrismorSec/prismor prismor.dev Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue t | 339 | Claude Code, Codex, OpenCode | 2 | 4,780 tok |
| m4xx101/cryptex-oss Open-source LLM red-teaming technique toolkit (162 transforms, 36 mutators, 25 tool surfac | 338 | Claude Code | 1 | 3,329 tok |
| smart-mcp-proxy/mcpproxy-go mcpproxy.app Supercharge AI Agents, Safely | 337 | Claude Code, Codex, OpenCode | 2 | 4,330 tok |
| adshao/flounder flounders.xyz Autonomous white-hat security auditor for AI-driven code review, bug bounty research, expl | 331 | Codex, OpenCode | 1 | 6,358 tok |
| cellebrite-labs/ghidra-rpc A Ghidra agentic reverse engineering skill. | 323 | Claude Code, Codex, OpenCode | 2 | 3,863 tok |