267 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,412Data and AI4,299Backend and APIs3,694Languages3,682Planning3,492Git and workflow3,285Code review2,942Memory and context2,581Research2,499Writing and docs2,458Testing2,454Frontend2,420
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorKiroWindsurf
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| affaan-m/ECC ecc.tools The agent harness performance optimization system. Skills, instincts, memory, security, an | 250,130 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 3,778 tok |
| electron/electron electronjs.org :electron: Build cross-platform desktop apps with JavaScript, HTML, and CSS | 122,901 | Claude Code, GitHub Copilot | 8 | 4,327 tok |
| rapid7/metasploit-framework metasploit.com Metasploit Framework | 38,946 | Codex, GitHub Copilot, OpenCode | 6 | 7,425 tok |
| mukul975/Anthropic-Cybersecurity-Skills mahipal.engineer 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, | 32,252 | Codex, GitHub Copilot, OpenCode | 2 | 5,015 tok |
| agentscope-ai/agentscope docs.agentscope.io Build and run agents you can see, understand and trust. | 30,816 | GitHub Copilot | 1 | 741 tok |
| analysis-tools-dev/static-analysis analysis-tools.dev ⚙️ A curated list of static analysis (SAST) tools and linters for all programming language | 14,766 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 4 | 344 tok |
| data-privacy-stack/presidio presidio.dataprivacystack.org An open-source framework for detecting, redacting, masking, and anonymizing sensitive data | 10,759 | Claude Code, Codex, GitHub Copilot, OpenCode | 5 | 6,710 tok |
| lldap/lldap Light LDAP implementation | 6,488 | GitHub Copilot | 1 | 1,992 tok |
| microsoft/agent-governance-toolkit AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxin | 6,204 | Codex, GitHub Copilot, OpenCode | 2 | 7,473 tok |
| FlorianBruniaux/claude-code-ultimate-guide cc.bruniaux.com The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, q | 5,903 | Claude Code, Codex, GitHub Copilot, OpenCode | 10 | 5,911 tok |
| dmno-dev/varlock varlock.dev AI-safe .env files: Schemas for agents, Secrets for humans. | 4,298 | Claude Code, Codex, GitHub Copilot, OpenCode | 6 | 2,320 tok |
| visa/visa-vulnerability-agentic-harness Visa Vulnerability Agentic Harness | 2,725 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 3,632 tok |
| pixeltable/pixeltable docs.pixeltable.com The unified multimodal backend for AI data apps. Database, orchestration, and serving in o | 1,618 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 7,174 tok |
| relaticle/relaticle relaticle.com Open-source CRM with native AI agent support. 37 MCP tools, REST API, self-hosted. Built w | 1,605 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 30 | 29,684 tok |
| microsoft/hve-core A refined collection of Hypervelocity Engineering components (instructions, prompts, agent | 1,436 | GitHub Copilot | 7 | 13,397 tok |
| justrach/codedb codegraff.com Zig code intelligence server and MCP toolset for AI agents. Fast tree, outline, symbol, se | 1,372 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 1,700 tok |
| vndee/llm-sandbox vndee.github.io Lightweight and portable LLM sandbox runtime (code interpreter) Python library. | 1,119 | Claude Code, GitHub Copilot | 2 | 4,844 tok |
| SafeAI-Lab-X/ClawKeeper ClawKeeper: Comprehensive Safety Protection for OpenClaw Agents Through Skills, Plugins, a | 1,023 | GitHub Copilot | 1 | 574 tok |
| pocketpaw/pocketpaw pocketpaw.xyz Your AI agent in 30 seconds. Not 30 hours. Self-hosted, open-source personal AI with deskt | 877 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 6,715 tok |
| agentscope-ai/agentscope-runtime runtime.agentscope.io A production-ready runtime framework for agent apps with secure tool sandboxing, Agent-as- | 863 | GitHub Copilot | 1 | 646 tok |
| cyberkaida/reverse-engineering-assistant MCP server for reverse engineering tasks in Ghidra 👩💻 | 822 | Claude Code, Codex, GitHub Copilot, OpenCode | 7 | 4,764 tok |
| H-mmer/pentest-agents Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and | 815 | Claude Code, Codex, GitHub Copilot, OpenCode | 17 | 63,845 tok |
| borghei/Claude-Skills borghei.github.io 368 AI skills, 76 expert agents, and 859 stdlib Python tools for every team: engineering, | 714 | Claude Code, Codex, GitHub Copilot, Cursor, Gemini CLI, OpenCode | 8 | 9,493 tok |
| emiliaprotocol/emilia-protocol emiliaprotocol.ai Authority control plane for autonomous work. EMILIA Gate enforces finite customer-owned ma | 649 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 1,680 tok |
| provos/ironcurtain ironcurtain.dev A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*htt | 601 | Claude Code, GitHub Copilot, Gemini CLI | 10 | 9,002 tok |
| thunder-id/thunderid thunderid.dev ThunderID is a high-performance, open-source identity stack designed for developers to sec | 574 | Claude Code, Codex, GitHub Copilot, OpenCode | 8 | 1,505 tok |
| nirholas/XActions xactions.app ⚡ The Complete X/Twitter Automation Toolkit — Scrapers, MCP server for AI agents (Claude/G | 510 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 11 | 8,439 tok |
| epam/ai-dial-chat chat.dialx.ai A default UI for AI DIAL | 504 | Claude Code, Codex, GitHub Copilot, Cursor, OpenCode | 48 | 4,341 tok |
| potatoqualitee/kbupdate 🛡 KB Viewer, Saver, Installer and Uninstaller | 390 | Claude Code, Codex, GitHub Copilot, OpenCode | 10 | 1,046 tok |
| mapbox/mcp-server Mapbox Model Context Protocol (MCP) server | 353 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 2,525 tok |
| lbx154/Argus A self-evolving multi-agent system for autonomous research, operating 24/7 to explore, lea | 301 | Claude Code, Codex, GitHub Copilot | 2 | 616 tok |
| ucsandman/DashClaw dashclaw.io Remote approvals, policy checks, and execution evidence for unattended AI agents. | 297 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 30 | 10,148 tok |
| eqtylab/cupcake cupcake.eqtylab.io A native policy enforcement layer for AI coding agents. Built on OPA/Rego. | 289 | Claude Code, GitHub Copilot | 3 | 12,811 tok |
| finos/git-proxy git-proxy.finos.org Deploy custom push protections and policies on top of Git | 246 | Claude Code, Codex, GitHub Copilot, OpenCode | 17 | 2,404 tok |
| SCStelz/security-investigator Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python | 244 | Claude Code, Codex, GitHub Copilot | 29 | 22,159 tok |
| bx33661/Wireshark-MCP Wireshark-MCP,Give your AI assistant a packet analyzer. Drop a .pcap file, ask questions i | 228 | Claude Code, GitHub Copilot | 3 | 235 tok |
| Garudex-Labs/caracal caracal.run 🐾 Authority, not credentials, for AI agents: policy-approved actions, delegation that can | 205 | Claude Code, GitHub Copilot | 19 | 4,434 tok |
| lennney/mcp-slim-guard take-a-deep-breath0.com Context compression for MCP. Same upstream call, exact results recoverable. | 192 | Claude Code, Codex, GitHub Copilot, OpenCode | 3 | 1,224 tok |
| wellwelwel/lagune lagune.ai 🌊 Lagune is your security copilot as you build, your Blue Team when you audit, whether yo | 147 | Claude Code, Codex, GitHub Copilot, Cursor, Gemini CLI, OpenCode | 5 | 2,636 tok |
| forefy/.context forefy.com AI Agent Skills, Goals and Dynamic Workflows for Security Auditing, Pentesting and Researc | 144 | Claude Code, GitHub Copilot | 2 | 249 tok |
| AndrewAltimit/template-repo andrewaltimit.github.io Agent orchestration & security template featuring MCP tool building, agent2agent workflows | 131 | Claude Code, Codex, GitHub Copilot, OpenCode | 4 | 4,140 tok |
| agutinbaigo28/financial-agent-api financial agent api with multi-agent framework for scalable AI systems focusing on financi | 129 | Claude Code, Codex, GitHub Copilot, OpenCode | 50 | 34,906 tok |
| fran-olivares/usulnet usulnet.com Open-source Docker infrastructure platform. One web UI — containers, security, DNS, VPN, m | 128 | GitHub Copilot | 1 | 2,716 tok |
| hiromaily/go-crypto-wallet Cryptocurrency wallet for trading for Bitcoin, Bitcoin cash, Ethereum, ERC20, XRP Leger (R | 127 | Claude Code, Codex, GitHub Copilot, OpenCode | 6 | 3,234 tok |
| nirholas/pump-fun-sdk sdk.pumpk.it Token creation launching, bonding curve trading, AMM migration, tiered fees, creator fee s | 118 | Claude Code, Codex, GitHub Copilot, Gemini CLI, OpenCode | 4 | 7,518 tok |
| DFKHelper/token-goat npmjs.com Token burn reducer and focus keeper for Claude Code, Codex, Copilot, Gemini CLI, and more: | 112 | Codex, GitHub Copilot, OpenCode | 2 | 2,578 tok |
| microsoft/vscode-copilotstudio VS Code Extension for Copilot Studio | 108 | Claude Code, Codex, GitHub Copilot, OpenCode | 6 | 6,765 tok |
| microsoft/Agent365-Samples | 107 | Claude Code, GitHub Copilot | 11 | 5,728 tok |
| microsoft/PromptKit Agentic prompts are the most important code you're not engineering. PromptKit fixes that — | 104 | GitHub Copilot | 1 | 1,144 tok |
| faramesh/faramesh-core docs.faramesh.dev Governance-as-Code for AI agents. Declarative constraints with deterministic enforcement. | 102 | GitHub Copilot | 1 | 210 tok |