1,084 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,412Data and AI4,299Backend and APIs3,694Languages3,682Planning3,492Git and workflow3,285Code review2,942Memory and context2,581Research2,499Writing and docs2,458Testing2,454Frontend2,420
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorKiroWindsurf
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| affaan-m/ECC ecc.tools The agent harness performance optimization system. Skills, instincts, memory, security, an | 250,130 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 3,778 tok |
| usestrix/strix strix.ai Open-source AI penetration testing tool to find and fix your app’s vulnerabilities. | 60,777 | Codex, OpenCode | 1 | 1,847 tok |
| colinhacks/zod zod.dev TypeScript-first schema validation with static type inference | 43,847 | Claude Code, Codex, Cursor, OpenCode | 5 | 5,780 tok |
| danny-avila/LibreChat librechat.ai Enhanced ChatGPT Clone: Features Agents, MCP, Skills, DeepSeek, Anthropic, AWS, OpenAI, Re | 42,847 | Claude Code, Codex, OpenCode | 2 | 4,147 tok |
| rapid7/metasploit-framework metasploit.com Metasploit Framework | 38,946 | Codex, GitHub Copilot, OpenCode | 6 | 7,425 tok |
| zhaoxuya520/reverse-skill Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack | 34,719 | Claude Code, Codex, OpenCode | 2 | 1,078 tok |
| OWASP/CheatSheetSeries cheatsheetseries.owasp.org The OWASP Cheat Sheet Series was created to provide a concise collection of high value inf | 33,087 | Claude Code, Codex, OpenCode | 2 | 2,094 tok |
| mukul975/Anthropic-Cybersecurity-Skills mahipal.engineer 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, | 32,252 | Codex, GitHub Copilot, OpenCode | 2 | 5,015 tok |
| activepieces/activepieces activepieces.com AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automati | 24,286 | Claude Code, Codex, OpenCode | 22 | 9,534 tok |
| semgrep/semgrep semgrep.dev Lightweight static analysis for many languages. Find bug variants with patterns that look | 16,525 | Claude Code, Codex, OpenCode | 2 | 2,020 tok |
| analysis-tools-dev/static-analysis analysis-tools.dev ⚙️ A curated list of static analysis (SAST) tools and linters for all programming language | 14,766 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 4 | 344 tok |
| prowler-cloud/prowler prowler.com Prowler is the world’s most widely used open-source cloud security platform that automates | 14,759 | Claude Code, Codex, OpenCode | 2 | 2,928 tok |
| blackboardsh/electrobun blackboard.sh Build ultra fast, tiny, and cross-platform desktop apps with Typescript. | 12,762 | Claude Code, Codex | 2 | 371 tok |
| TencentCloud/CubeSandbox cubesandbox.com Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents. | 11,808 | Claude Code, Codex, OpenCode | 11 | 232 tok |
| data-privacy-stack/presidio presidio.dataprivacystack.org An open-source framework for detecting, redacting, masking, and anonymizing sensitive data | 10,747 | Claude Code, Codex, GitHub Copilot, OpenCode | 5 | 6,710 tok |
| NVIDIA/garak discord.gg the LLM vulnerability scanner | 9,120 | Codex, OpenCode | 1 | 1,415 tok |
| NVIDIA/OpenShell docs.nvidia.com OpenShell is the safe, private runtime for autonomous AI agents. | 8,517 | Claude Code, Codex, OpenCode | 22 | 4,796 tok |
| backnotprop/plannotator plannotator.ai Annotate and review coding agent plans and code diffs visually, share with your team, send | 8,463 | Claude Code, Codex, OpenCode | 6 | 35,880 tok |
| kunchenguid/no-mistakes kunchenguid.github.io git push no-mistakes | 8,312 | Claude Code, Codex, OpenCode | 17 | 5,764 tok |
| superradcompany/microsandbox docs.microsandbox.dev 🧱 easy fast local-first microVM runtime and library | 8,091 | Codex, OpenCode | 1 | 3,652 tok |
| zeek/zeek zeek.org Zeek is a powerful network analysis framework that is much different from the typical IDS | 7,941 | Codex, OpenCode | 1 | 823 tok |
| trailofbits/skills Trail of Bits Claude Code skills for security research, vulnerability detection, and audit | 6,978 | Claude Code, Codex, OpenCode | 2 | 4,752 tok |
| j3ssie/osmedeus osmedeus.org A Modern Orchestration Engine for Security | 6,549 | Claude Code, Codex, OpenCode | 2 | 8,804 tok |
| microsoft/agent-governance-toolkit AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxin | 6,204 | Codex, GitHub Copilot, OpenCode | 2 | 7,473 tok |
| Tencent/AI-Infra-Guard tencent.github.io A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, M | 6,151 | Claude Code, Codex, OpenCode | 2 | 2,177 tok |
| FlorianBruniaux/claude-code-ultimate-guide cc.bruniaux.com The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, q | 5,903 | Claude Code, Codex, GitHub Copilot, OpenCode | 10 | 5,911 tok |
| mock-server/mockserver-monorepo mock-server.com MockServer is an HTTP(S) mock server and proxy for testing that lets you mock APIs, inspec | 4,965 | Claude Code, Codex, OpenCode | 61 | 7,403 tok |
| Awarexone/Agentic-Bug-Hunter awarexone.com AI-powered bug bounty hunting toolkit that works with or without subscription. | 4,710 | Claude Code, Codex, OpenCode | 4 | 5,851 tok |
| mvanhorn/cli-printing-press Every API has a secret identity. This finds it, absorbs every feature from every competing | 4,635 | Claude Code, Codex, OpenCode | 4 | 10,111 tok |
| firebase/firebase-tools The Firebase Command Line Tools | 4,463 | Claude Code, Codex, Gemini CLI | 3 | 769 tok |
| dmno-dev/varlock varlock.dev AI-safe .env files: Schemas for agents, Secrets for humans. | 4,298 | Claude Code, Codex, GitHub Copilot, OpenCode | 6 | 2,320 tok |
| nolabs-ai/nono nono.sh secure multiplexed execution paths for agents - zero trust, zero setup, zero latency. | 3,978 | Claude Code, Codex, OpenCode | 2 | 2,527 tok |
| ilysenko/codex-desktop-linux Unofficial ChatGPT desktop app for Linux (formerly the Codex app), built locally from Open | 3,769 | Codex, OpenCode | 1 | 1,444 tok |
| nextlevelbuilder/goclaw goclaw.sh GoClaw - GoClaw is OpenClaw rebuilt in Go — with multi-tenant isolation, 5-layer security, | 3,589 | Claude Code, Codex, OpenCode | 2 | 12,319 tok |
| langchain-ai/langgraphjs docs.langchain.com Framework to build resilient language agents as graphs. | 3,251 | Claude Code, Codex, OpenCode | 2 | 551 tok |
| TanStack/ai tanstack.com 🤖 Type-safe, provider-agnostic TypeScript AI SDK for streaming chat, tool calling, agents | 3,073 | Claude Code, Codex, OpenCode | 12 | 7,416 tok |
| chaterm/Chaterm chaterm.ai Open source AI terminal for cloud and infrastructure management, enabling you to deploy, t | 3,034 | Claude Code, Codex, OpenCode | 2 | 3,932 tok |
| ccch1mneyyy/dsh-TUI dshtui.com DSH official WeChat featured TUI plugin — Claude Code style: whale bar, live status, strea | 2,850 | Claude Code, Codex, OpenCode | 9 | 2,096 tok |
| LLMQuant/quant-mind llmquantdata.com QuantMind is an agent-native knowledge extraction and retrieval framework for quantitative | 2,814 | Claude Code, Codex, OpenCode | 5 | 2,264 tok |
| openlit/openlit docs.openlit.io Open source platform for AI Engineering: OpenTelemetry-native LLM Observability, GPU Monit | 2,742 | Claude Code, Codex, OpenCode | 4 | 829 tok |
| visa/visa-vulnerability-agentic-harness Visa Vulnerability Agentic Harness | 2,725 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 3,632 tok |
| SummerSec/ShiroAttack2 Comprehensive exploitation of Shiro deserialization vulnerabilities (for authorized testin | 2,624 | Claude Code, Codex, OpenCode | 3 | 2,182 tok |
| lestrrat-go/jwx Complete implementation of JWx (Javascript Object Signing and Encryption/JOSE) technologie | 2,420 | Claude Code, Codex, OpenCode | 3 | 3,061 tok |
| samugit83/redamon An AI-powered agentic red team framework that automates offensive security operations, fro | 2,403 | Claude Code, Codex, OpenCode | 2 | 2,279 tok |
| beenuar/AiSOC tryaisoc.com Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agen | 2,368 | Codex, OpenCode | 1 | 6,497 tok |
| zakirkun/deep-eye Deep Eye orchestrates multiple AI providers (OpenAI, Claude, Grok, Gemini, OLLAMA, Groq, M | 2,285 | Claude Code, Codex, OpenCode | 8 | 2,919 tok |
| 777genius/agent-teams-ai agentteams.live You're the boss, agents are your team. They handle tasks on their own, message each other, | 2,071 | Claude Code, Codex, OpenCode | 2 | 5,460 tok |
| m14r41/PentestingEverything pentesting.m14r41.in Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | 2,066 | Claude Code, Codex | 1 | — |
| Kritt-ai/open-kritt kritt.ai Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find a | 2,059 | Codex, OpenCode | 1 | 2,190 tok |
| eugene1g/agent-safehouse agent-safehouse.dev Sandbox your local AI agents so they can read/write only what they need | 2,050 | Claude Code, Codex, OpenCode | 3 | 1,353 tok |