975 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,410Claude Code6,578Data and AI3,695Backend and APIs3,487Languages3,404Planning3,188Git and workflow3,106Code review2,712Memory and context2,351Testing2,325Research2,289DevOps and cloud2,283
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| verygoodsecurity/vgs-collect-ios verygoodsecurity.com VGS Collect iOS SDK | 23 | Codex, OpenCode | 1 | 13 tok |
| gtasb/Burp-AI-Analyzer An AI-assisted penetration testing assistant developed with agentscope | 23 | Codex, OpenCode | 1 | 945 tok |
| sy159/snowgo A lightweight rapid-development Golang API project built with Gin + Gorm, ready to use out | 23 | Codex, OpenCode | 1 | 1,720 tok |
| GSA-TTS/agentic-coding-playbook Practical, tool-agnostic playbook for federal employees building software with AI coding a | 23 | Claude Code, Codex, OpenCode | 13 | 10,717 tok |
| gromhacks/bonsai-ninja 🥷 Give your codebase a black belt. Local code intelligence, security analysis, and compil | 23 | Claude Code, Codex, OpenCode | 2 | 6,225 tok |
| Elnora-AI/elnora-ai-agent-hackathon-starter-kit Run one command, follow the instructions, and get your first AI agents up and running — Cl | 22 | Claude Code, Codex, OpenCode | 3 | 3,892 tok |
| ShieldNet-360/secure-vibe SecureVibe — prevention-first security for AI-written code. Signed SKILL.md knowledge that | 22 | Codex, OpenCode | 1 | 1,449 tok |
| meltedinhex/analyst-ai-pack meltedinhex.com An open agent-skills library for malware analysis, reverse engineering, and threat hunting | 22 | Codex, GitHub Copilot, OpenCode | 2 | 1,536 tok |
| ducnguyen67201/FeatherlaneAI featherlane.ai Real-time guardrail runtime for AI agents. | 22 | Claude Code, Codex, OpenCode | 2 | 4,375 tok |
| atlanhq/atlan-python docs.atlan.com Official Python SDK for the Atlan 💙 | 22 | Claude Code, Codex, OpenCode | 6 | 1,222 tok |
| fdhhhdjd/Class-Production-AI-App 🏗️ Production-ready AI app structure — RAG pipeline, hybrid search, self-correcting agent | 22 | Claude Code, Codex, OpenCode | 2 | 776 tok |
| mrFlick72/vauthenticator VAuthenticator OpenID Connect/OAuth2.1 Auth server | 22 | Claude Code, Codex, OpenCode | 2 | 207 tok |
| fpytloun/intaris Guardrails service for AI agents. Default-deny tool call evaluation with LLM safety analys | 22 | Codex, OpenCode | 1 | 22,010 tok |
| VincentChuWaiChow/vanguard-frontier-agentic Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance- | 22 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 5,843 tok |
| kalpmodi/akira Autonomous offensive security agent. Plans engagements, runs recon, chains exploits, and w | 21 | Codex, OpenCode | 1 | 575 tok |
| gaspareduard/Omada-mcp Security-first MCP server for TP-Link Omada, with a stdio-first runtime, capability-gated | 21 | Claude Code, Codex, OpenCode | 3 | 2,700 tok |
| woohyun212/security-skill A collection of AI agent skills for security professionals, by security professionals, and | 21 | Claude Code, Codex, OpenCode | 2 | 1,284 tok |
| Onurlulardan/ForgeStart Production-ready Next.js SaaS starter with Auth.js, Drizzle, PostgreSQL, RBAC, admin UI, i | 21 | Codex, OpenCode | 1 | 2,406 tok |
| Trivo25/code-airlock trivo25.github.io Run Claude Code (or another coding agent) unattended, inside a disposable microVM, with it | 20 | Claude Code, Codex, OpenCode | 2 | 288 tok |
| royashbrook/hush royashbrook.com a secret store for ai agents with one rule: the agent never sees the plaintext. get a secr | 20 | Codex, OpenCode | 1 | 410 tok |
| pantheraudits/move-auditor pantheraudits.com Skill for move smart contract security auditing. | 20 | Claude Code, Codex, OpenCode | 2 | 1,607 tok |
| tower/agentic-data-engineering Repository with a skills boilerplate for agentic data engineering workflows | 20 | Claude Code, Codex, OpenCode | 5 | 1,154 tok |
| pierreb-devkit/Node weareopensource.me :computer: Node - Boilerplate Back : Express, Jwt, Mongo, Sequelize | 20 | Claude Code, Codex, GitHub Copilot, OpenCode | 4 | 2,293 tok |
| aldegad/safedeps npmjs.com Dependency safety gate for Claude Code & Codex CLI — OSV pre-approval, npm lockfile-closur | 20 | Claude Code, Codex, OpenCode | 2 | 4,254 tok |
| PandaNePanda/notioncode_mcp t.me MCP that allows you to use top-tier LLM's, such as GPT-5.6 and Fable 5, in any IDE via Not | 19 | Codex, OpenCode | 1 | 553 tok |
| yultyyev/better-auth-firebase-auth npmjs.com Use Firebase Authentication (Phone SMS OTP, Google, Email) with Better Auth sessions, orga | 19 | Codex, OpenCode | 1 | 2,238 tok |
| Bugb-Technologies/guardlink guardlink.bugb.io AI-maintained security annotations for code. Continuous threat modeling, enforced in CI. | 19 | Claude Code, Codex, GitHub Copilot, OpenCode, Windsurf | 4 | 14,840 tok |
| aws-samples/sample-multi-tenant-saas-mcp-server Multi-Tenant remote MCP server with Amazon Cognito and remote client with Amazon Bedrock h | 19 | Codex, OpenCode | 1 | 1,007 tok |
| SkyShannonProver/shannon-prover skyshannonprover.github.io LLM agents that write machine-checked cryptographic proofs in EasyCrypt (arXiv:2607.02847) | 19 | Claude Code, Codex, OpenCode | 4 | 2,653 tok |
| safe-agentic-world/nomos Secure every action your AI agents take (Claude Code, Codex, MCP). Blocks secret access, g | 18 | Claude Code, Codex, OpenCode | 2 | 2,211 tok |
| pluginslab/wp-agentic-kit pluginslab.com Starter kit for agentic WordPress development. CLAUDE.md/AGENTS.md templates, the wordpres | 18 | Claude Code, Codex, OpenCode | 8 | 3,997 tok |
| aiconnai/agentshield aiconnai.github.io 🛡️ The security firewall for AI agent tools & MCP servers (Claude, GPT-5.6, Gemini 3.7, A | 18 | Claude Code, Codex, OpenCode | 2 | 7,115 tok |
| ssdeanx/secure-rag-multi-agent deanmachines.com Secure Retrieval-Augmented Generation (RAG) with role-based access control using Mastra AI | 18 | Codex, GitHub Copilot, OpenCode | 3 | 15,972 tok |
| staticroostermedia-arch/engram glama.ai Geometric agent memory for Agents: 8-tool lean contract, harness injection at wake, sessio | 18 | Claude Code, Codex, OpenCode | 2 | 3,188 tok |
| nexus-substrate/nexus-agents nexus-substrate.github.io Governance substrate for your AI coding agents — adversarial review, drift-detected rules, | 18 | Claude Code, Codex, Gemini CLI, OpenCode | 7 | 26,903 tok |
| kingggg5/shipproof shipproof-site.sjet2744.chatgpt.site Evidence-first Codex, Claude plugin for bugs, security, and 10k-to-1M-user scale readiness | 18 | Claude Code, Codex, Gemini CLI, OpenCode | 3 | 1,055 tok |
| ajipurn/fida fida.my.id a local-first secret leak prevention layer for AI coding agents | 18 | Codex, OpenCode | 1 | 129 tok |
| Liberty91LTD/cti-skills liberty91.com Cyber Threat Intelligence Skills for each stage of the CTI Lifecycle. | 17 | Claude Code, Codex, OpenCode | 4 | 2,048 tok |
| clouisle/Clouisle clouisle.asia Next-Generation Multi-Agent Collaboration Platform and Workflow Engine. Build and orchestr | 17 | Claude Code, Codex, OpenCode | 2 | 529 tok |
| icefrag/nbl-superpowers The agent harness performance optimization system. Skills, instincts, memory, security, an | 17 | Codex, OpenCode | 1 | 57 tok |
| AppliedIR/sift-mcp appliedir.github.io Valhuntir SIFT platform — MCP servers, gateway, Examiner Portal | 17 | Codex, OpenCode | 1 | 2,318 tok |
| XZXZZX-Ai/bilibili-mcp Bilibili MCP tool A Bilibili MCP server | 17 | Claude Code, Codex, OpenCode | 14 | 1,197 tok |
| Eilodon/CALM npmjs.com A live, graph-verified map of your codebase for AI coding agents — real call graphs, compi | 16 | Claude Code, Codex, OpenCode | 7 | 7,514 tok |
| appsec-foundry/appsec-advisor Claude Code plugin for code-anchored threat modeling and security architecture review. | 16 | Claude Code, Codex, OpenCode | 4 | 1,845 tok |
| ashlrai/phantom-secrets phm.dev Stop AI coding agents from leaking your API keys. Local proxy + MCP that swaps real secret | 16 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 4 | 5,984 tok |
| authprobe/authprobe authprobe.com authprobe pinpoints MCP OAuth failures | 16 | Codex, OpenCode | 1 | 1,121 tok |
| renatobardi/hapai renatobardi.github.io Deterministic guardrails for AI coding assistants. Enforce rules via Bash hooks before exe | 16 | Claude Code, Codex, OpenCode | 2 | 13,646 tok |
| oscal-compass-lab/compliance-trestle-skills Agent-portable Compliance Trestle and OSCAL engineering toolkit: convert legacy SSPs to OS | 16 | Claude Code, Codex, Gemini CLI, OpenCode | 2 | 1,658 tok |
| whitequeen306/code-cortex-loop One-command AI code quality pipeline: review, security, tests, performance, simplify & cle | 16 | Codex, OpenCode | 1 | 1,601 tok |
| iOSDevSK/mcp-for-woocommerce mcpforwoocommerce.com WooCommerce MCP Server — WordPress community plugin implementing the Model Context Protoco | 15 | Codex, OpenCode | 1 | 1,039 tok |