1,026 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,374Claude Code6,573Data and AI3,706Backend and APIs3,486Languages3,398Planning3,181Git and workflow3,100Code review2,701Memory and context2,354Testing2,311Research2,292DevOps and cloud2,282
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| nik1t7n/context-firewall Local-first context firewall for coding agents | 26 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 358 tok |
| JeongJaeSoon/agent-guard Real-time secret-leak guardrails for AI coding agents (Claude Code, Codex), Git hooks, and | 26 | Codex, OpenCode | 1 | 235 tok |
| barvhaim/HoneyMCP A Deception Security Layer for MCP Servers. It injects "ghost tools" (fake security-sensit | 25 | Claude Code, Codex, OpenCode | 2 | 4,918 tok |
| matteocervelli/llms Centralized LLM configuration and documentation management system. Tools for building skil | 25 | Claude Code, Codex | 39 | 347 tok |
| allsmog/vuln-scout AI-powered whitebox penetration testing plugin for Claude Code. 9 languages, 22 skills, 7 | 24 | Claude Code, Codex, OpenCode | 2 | 1,307 tok |
| anasfik/FlutterGuard Flutter APK/AAB security SKILL.md for OpenClaw, Codex, Claude Code, and other AI coding ag | 24 | Codex, OpenCode | 1 | 434 tok |
| ali-master/audit audit.usestrict.dev An 8-stage AI vulnerability-discovery agent. | 24 | Claude Code, Codex | 2 | — |
| xinxin7/claw-shield The governance layer for AI agents — monitor reasoning, audit tool calls, and secure the l | 24 | Codex, OpenCode | 1 | 2,046 tok |
| r5rana/agentware Framework that makes your LLM self-aware, loops with self-learning and persistent memory t | 24 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 34 | 4,731 tok |
| qauth-labs/qauth qauth.dev Post-quantum ready, headless-first identity platform. A developer-friendly alternative to | 24 | Claude Code, Codex, OpenCode | 30 | 1,621 tok |
| badbread/crumbvms crumbvms.com A self-hosted, operator-grade NVR for your own security cameras: recording, motion, licens | 24 | Claude Code, Codex, OpenCode | 2 | 2,361 tok |
| IgorWarzocha/opencode-usage-plugin Plugin that displays your OAuth subscription quotas. | 24 | Codex, OpenCode | 1 | 325 tok |
| fiberplane/mcp-gateway Gateway for inspecting and auditing your MCP servers | 24 | Claude Code, Codex, OpenCode | 2 | 5,849 tok |
| rayline-ai/rayline rayline.ai Open-source local router for coding agents, connecting Claude Code to cloud and local on-d | 24 | Claude Code, Codex, OpenCode | 2 | 961 tok |
| MythicAgents/sage Sage is a virtual Mythic agent that that uses an AI agentic system to operate Mythic and M | 24 | Claude Code, Codex, OpenCode | 6 | 11,687 tok |
| zhouwei713/WorkBuddy-Dream-Skin Community image-driven skin for Tencent WorkBuddy desktop. External CDP injection, fully r | 24 | Codex, OpenCode | 1 | 826 tok |
| wangjianjq/Skill Auto agents | 23 | Claude Code, Codex, GitHub Copilot, Cursor, Gemini CLI, OpenCode | 45 | 8,297 tok |
| depalmar/ai-dfir-toolkit A vendor-neutral collection of Sigma, YARA, and Suricata rules for detecting compromise of | 23 | Claude Code, Codex | 1 | 6,013 tok |
| RobithYusuf/mcp-stealth-chrome Stealth Chrome MCP server — 100++ tools for AI agents. One-liner Cloudflare Turnstile bypa | 23 | Claude Code, Codex, OpenCode | 2 | 4,147 tok |
| verygoodsecurity/vgs-collect-ios verygoodsecurity.com VGS Collect iOS SDK | 23 | Codex, OpenCode | 1 | 13 tok |
| fb0sh/pentester An automated penetration testing framework based on AI agents, strictly following the PTES | 23 | Claude Code, Codex | 58 | — |
| gtasb/Burp-AI-Analyzer An AI-assisted penetration testing assistant developed with agentscope | 23 | Codex, OpenCode | 1 | 945 tok |
| sy159/snowgo A lightweight rapid-development Golang API project built with Gin + Gorm, ready to use out | 23 | Codex, OpenCode | 1 | 1,720 tok |
| GSA-TTS/agentic-coding-playbook Practical, tool-agnostic playbook for federal employees building software with AI coding a | 23 | Claude Code, Codex, OpenCode | 13 | 10,717 tok |
| gromhacks/bonsai-ninja 🥷 Give your codebase a black belt. Local code intelligence, security analysis, and compil | 23 | Claude Code, Codex, OpenCode | 2 | 6,007 tok |
| Elnora-AI/elnora-ai-agent-hackathon-starter-kit Run one command, follow the instructions, and get your first AI agents up and running — Cl | 22 | Claude Code, Codex, OpenCode | 3 | 3,892 tok |
| ShieldNet-360/secure-vibe SecureVibe — prevention-first security for AI-written code. Signed SKILL.md knowledge that | 22 | Codex, OpenCode | 1 | 1,449 tok |
| meltedinhex/analyst-ai-pack meltedinhex.com An open agent-skills library for malware analysis, reverse engineering, and threat hunting | 22 | Codex, GitHub Copilot, OpenCode | 2 | 1,536 tok |
| ducnguyen67201/FeatherlaneAI featherlane.ai Real-time guardrail runtime for AI agents. | 22 | Claude Code, Codex, OpenCode | 2 | 4,375 tok |
| atlanhq/atlan-python docs.atlan.com Official Python SDK for the Atlan 💙 | 22 | Claude Code, Codex, OpenCode | 6 | 1,222 tok |
| fdhhhdjd/Class-Production-AI-App 🏗️ Production-ready AI app structure — RAG pipeline, hybrid search, self-correcting agent | 22 | Claude Code, Codex, OpenCode | 2 | 776 tok |
| mrFlick72/vauthenticator VAuthenticator OpenID Connect/OAuth2.1 Auth server | 22 | Claude Code, Codex, OpenCode | 2 | 207 tok |
| pandysp/openclaw-infra Secure self-hosted OpenClaw deployment on Hetzner Cloud with Tailscale | 22 | Claude Code, Codex | 1 | 7,404 tok |
| fpytloun/intaris Guardrails service for AI agents. Default-deny tool call evaluation with LLM safety analys | 22 | Codex, OpenCode | 1 | 22,010 tok |
| VincentChuWaiChow/vanguard-frontier-agentic Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance- | 22 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 5,843 tok |
| kalpmodi/akira Autonomous offensive security agent. Plans engagements, runs recon, chains exploits, and w | 21 | Codex, OpenCode | 1 | 575 tok |
| gaspareduard/Omada-mcp Security-first MCP server for TP-Link Omada, with a stdio-first runtime, capability-gated | 21 | Claude Code, Codex, OpenCode | 3 | 2,700 tok |
| woohyun212/security-skill A collection of AI agent skills for security professionals, by security professionals, and | 21 | Claude Code, Codex, OpenCode | 2 | 1,284 tok |
| Onurlulardan/ForgeStart Production-ready Next.js SaaS starter with Auth.js, Drizzle, PostgreSQL, RBAC, admin UI, i | 21 | Codex, OpenCode | 1 | 2,406 tok |
| Trivo25/code-airlock trivo25.github.io Run Claude Code (or another coding agent) unattended, inside a disposable microVM, with it | 20 | Claude Code, Codex, OpenCode | 2 | 288 tok |
| royashbrook/hush royashbrook.com a secret store for ai agents with one rule: the agent never sees the plaintext. get a secr | 20 | Codex, OpenCode | 1 | 410 tok |
| pantheraudits/move-auditor pantheraudits.com Skill for move smart contract security auditing. | 20 | Claude Code, Codex, OpenCode | 2 | 1,607 tok |
| tower/agentic-data-engineering Repository with a skills boilerplate for agentic data engineering workflows | 20 | Claude Code, Codex, OpenCode | 5 | 1,154 tok |
| PandaNePanda/notioncode_mcp t.me MCP that allows you to use top-tier LLM's, such as GPT-5.6 and Fable 5, in any IDE via Not | 20 | Codex, OpenCode | 1 | 553 tok |
| pierreb-devkit/Node weareopensource.me :computer: Node - Boilerplate Back : Express, Jwt, Mongo, Sequelize | 20 | Claude Code, Codex, GitHub Copilot, OpenCode | 4 | 2,293 tok |
| aldegad/safedeps npmjs.com Dependency safety gate for Claude Code & Codex CLI — OSV pre-approval, npm lockfile-closur | 20 | Claude Code, Codex, OpenCode | 2 | 4,254 tok |
| yultyyev/better-auth-firebase-auth npmjs.com Use Firebase Authentication (Phone SMS OTP, Google, Email) with Better Auth sessions, orga | 19 | Codex, OpenCode | 1 | 2,238 tok |
| Bugb-Technologies/guardlink guardlink.bugb.io AI-maintained security annotations for code. Continuous threat modeling, enforced in CI. | 19 | Claude Code, Codex, GitHub Copilot, OpenCode, Windsurf | 4 | 14,736 tok |
| aws-samples/sample-multi-tenant-saas-mcp-server Multi-Tenant remote MCP server with Amazon Cognito and remote client with Amazon Bedrock h | 19 | Codex, OpenCode | 1 | 1,007 tok |
| SkyShannonProver/shannon-prover skyshannonprover.github.io LLM agents that write machine-checked cryptographic proofs in EasyCrypt (arXiv:2607.02847) | 19 | Claude Code, Codex, OpenCode | 4 | 2,653 tok |