5 projects whose own agent configuration covers security. These are not mods to install — they are how the maintainers of these repositories tell an agent what to do, and what to avoid.
All projects Building agents7,374Claude Code6,573Data and AI3,706Backend and APIs3,486Languages3,398Planning3,181Git and workflow3,100Code review2,701Memory and context2,354Testing2,311Research2,292DevOps and cloud2,282
Any agent Claude CodeCodexOpenCodeGitHub CopilotGemini CLICursorWindsurfKiro
| Project | Stars | Configures | Files | Always loaded |
|---|---|---|---|---|
| Paresh-Maheshwari/morphe-ai Morphe's AI-powered Android APK patching workspace — multi-agent pipeline for APK analysis | 154 | Codex, Kiro, OpenCode | 14 | 1,643 tok |
| aws-samples/appmod-blueprints | 103 | Claude Code, Kiro | 18 | — |
| awslabs/threat-modeling-mcp-server | 100 | Kiro | 10 | — |
| jgiox/goodvibes One command. Production-grade project. No config. | 4 | Claude Code, Codex, GitHub Copilot, Gemini CLI, Kiro, OpenCode, Windsurf | 15 | 6,796 tok |
| rosselps/whyguard npmjs.com Reconstructs why code exists and stops humans or agents from erasing that protection by ac | 0 | Claude Code, Codex, Kiro, OpenCode | 6 | 4,673 tok |