#owasp
GitHub repositories that have self-applied the topic "owasp" — a creator-tagged metadata that surfaces how AI projects describe themselves.
REPOS Repos for #owasp (top 17 by stars)
实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun 案例统计
woshilaohei/border-guardBorder Guard — AI-native territory sovereignty & self-evolving security OS. 6-module D-S fusion engine, trajectory detection, anchor detection, fission engine, territory adjudicator. Full design + Python implementation.
ArisRhiannon/vibecheckOffline, no-AI "safe to ship?" gate for vibe-coded apps — finds the security mistakes AI coding agents make (secrets, unprotected routes, eval-RCE, SQLi, CORS, JWT, leaked keys). CLI + MCP, agent-runnable.
Zeni-By-Zentra/sqa-agentSoftware Quality Assurance Agent para Claude Code — ISO/IEC 25010, OWASP, ISO 27001
jacobideji/aiiroverlayAI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0, OWASP Top 10 for Agentic Applications 2026, ISO/IEC 42001, EU AI Act.
snowflakeovo/cmdi-command-injectionSecurity testing skill for OS command injection and argument injection. Claude Code skill format.
aguleykovn8n/security-audit-skillUniversal security audit skill for Claude Code — OWASP Top 10 (2021) + Russian security standards (ГОСТ Р 56939, ФСТЭК, ФЗ-152) + STRIDE threat modeling. Multi-stack: Node/Python/Go/Rust.
m524security/HIVEBREACHAutonomous multi-agent AI penetration testing framework — 20 specialist agents, ECC architecture, MITRE ATT&CK + OWASP mapped, HMAC-chained audit trail, Docker sandbox, and multi-LLM backend (Ollama/OpenAI/Anthropic).
MohammedAl-Alimi/agent-security-playbookDefense-in-depth security rules AI coding agents can follow, and verify. 16 rule chapters, checklists, drop-in CLAUDE.md, self-verification test patterns.
MAUROCERON/ai-agent-security-mini-auditFree AI-agent risk self-check, security checklist, and USD 59 launch-readiness mini-audit offer.
kapus-hq/kapus-secuauditAudit your vibe-coded app for security holes (secrets, RLS, auth, injection, config), score it, and — with your approval — fix them in your code. A Claude Code / Codex skill. By Kapus.
CrampsP/sentinelforgeLocal-first security release checker for authorized code, AI apps, freelancers, and small teams
KonstiJo/pentest-report-skillAudit-ready pentest reports (DE/EN) with built-in compliance checks for BSI, OWASP, PCI-DSS, DiGA & OSCP. A Claude skill + standalone Python pipeline.
ahmadalhaish-tickit/client-secret-exposure-skillClaude Code skill for auditing Next.js apps for secrets exposed in the client JS bundle
Eastern-comptrollership272/crucible-Route coding tasks through an automated 8-agent pipeline for optimized, secure, and production-ready code output in Claude Code.
0xf4r/vyroscanSecurity auditor and scanner for AI-built (vibe-coded) apps — a Claude Code skill + standalone cross-stack scanner.
SARA8933326H/agent-surface-mappingAuthorized attack-surface discovery: Playwright crawler + safe vulnerability detection (headers, TLS, CORS, exposed files, GraphQL) + OWASP/CWE risk mapping, interactive Next.js dashboard, PDF/MD/JSON reports
RELATED Other topics · full topics ranking →
#claude-code
1,555#ai-agents
1,156#llm
1,066#claude
936#python
802#ai
737#developer-tools
723#mcp
719#codex
517Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology