AI Dev Impact Lab JA
← Topics ranking · 2026-08
GITHUB TOPIC

#appsec

GitHub repositories that have self-applied the topic "appsec" — a creator-tagged metadata that surfaces how AI projects describe themselves.

12
tagged repos
35
top 12 stars
7
with tool sigs
12
shown

REPOS Repos for #appsec (top 12 by stars)

Teycir/Assumptions

A SKILL that turns a code diff into an evidence-backed ledger of hidden assumptions, failure modes, and falsification tests.

TypeScript 18 AI 70 2 sig
NovaCode37/claude-security-skills

Production-ready Claude Code skills for cybersecurity — secret scanning, SAST, prompt-injection testing, HTTP/JWT/dependency auditing. Zero dependencies.

Python 11 AI 100
bmendonca3/authzbench-saas

Benchmark for AI agents proving multi-tenant SaaS authorization bugs

Python 2 AI 70 1 sig
foiovituh/patch-lens

AI-powered AppSec reviews for Git commits 🩹

Python 2 AI 70
hlsitechio/claude-skills-security

Defensive security audit skills for Claude — tech-stack-keyed and audit-domain-keyed packs for SaaS apps.

Shell 1 AI 100 1 sig
thedatakey/apollyon

Source code security scanner for human-written and AI-generated projects. Rust CLI with explicit coverage, JSON/SARIF, and coding-agent integrations. Built by Tom Koentjes. Pre-alpha.

Rust 1 AI 70 4 sig
kapus-hq/kapus-secuaudit

Audit your vibe-coded app for security holes (secrets, RLS, auth, injection, config), score it, and — with your approval — fix them in your code. A Claude Code / Codex skill. By Kapus.

Shell 0 AI 70 1 sig
ahmadalhaish-tickit/client-secret-exposure-skill

Claude Code skill for auditing Next.js apps for secrets exposed in the client JS bundle

0 AI 70 1 sig
Quant-Off/skills

Claude Code plugin marketplace for security auditing. evidence-based skills for constant-time crypto review, compiler-survival checks in binaries, and zero-trust codebase audits.

Python 0 AI 70 1 sig
0xf4r/vyroscan

Security auditor and scanner for AI-built (vibe-coded) apps — a Claude Code skill + standalone cross-stack scanner.

Shell 0 AI 70
JSiapoDEV/vibeward

Stops the insecure prompt before your AI agent runs it - and audits what it already shipped. Deterministic Claude Code guardrail (no LLM) catching "disable RLS" or "service_role in the frontend" in en/es/pt, plus a read-only scanner for exposed secrets, open Supabase RLS and Firebase leaks.

TypeScript 0 AI 70 Solo live ↗
SYCO7/codemoat

Security scanner for AI-generated code — GitHub Action + CLI wrapping Semgrep, Gitleaks, and an AI-agent-specific rule pack.

TypeScript 0 AI 60 Solo live ↗

RELATED Other topics · full topics ranking →

#claude-code

1,555

#ai-agents

1,156

#llm

1,066

#claude

936

#python

802

#ai

737

#developer-tools

723

#mcp

719

#codex

517

Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology