AI Dev Impact Lab JA
← Topics ranking · 2026-08
GITHUB TOPIC

#security

GitHub repositories that have self-applied the topic "security" — a creator-tagged metadata that surfaces how AI projects describe themselves.

103
tagged repos
690
top 40 stars
10
with tool sigs
40
shown

REPOS Repos for #security (top 40 by stars)

MyuriKanao/src-hunter-skill

实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun 案例统计

598 AI 70
ByteRay-AI/Xpsd

Reachability triage for vulnerability scans. Feeds scanner findings to an LLM agent that reads your source and decides which CVEs are actually reachable.

Go 13 AI 45
RefuseHQ/refuse

Open-source server that refuses vulnerable package installs. The backend the refuse CLI shim calls.

TypeScript 10 AI 45 live ↗
AppThreat/chennai

chennai (chen N ai) is a hybrid AI agent and a terminal user interface for static analysis, data-flow tracing, and AI-assisted code and security analysis.

Rust 5 AI 100
proluct/skanna

Security scanner for Claude Code skills, plugins, and MCP servers. A verdict before you install.

5 AI 70 1 sig
ralfyishere/agent-zero-trust

Zero-trust repo intake for AI coding agents — scan the instruction environment before Claude Code, Cursor, Codex, or Gemini touches a repo. Ships its own false-negative ledger.

Python 4 AI 100
decksoftware/csreview

Development-time local workspace security alignment for AI coding agents

JavaScript 4 AI 70
Actenon/actenon-scan

Find where agent-controlled intent reaches consequential actions without an authority check. Python + TypeScript + Go. Zero-dependency SAST for AI agents.

Python 4 AI 70
5uprem4/ai-skill-vault

Master AI Skills Collection 2026 - Scalable Agent Scripts & Automation Hub

HTML 3 AI 100
hannsxpeter/ready-suite

Ten composable AI skills covering the full arc from idea to launch. Discovery hub for prd-ready, architecture-ready, roadmap-ready, stack-ready, repo-ready, production-ready, deploy-ready, observe-ready, launch-ready, harden-ready. Plug into Claude Code, Codex, Cursor, Windsurf.

Shell 3 AI 70 1 sig
Yahor777/repopilot-bridge

🔒 Кросс-платформенный локальный мост для AI coding agents: Windows, macOS и Linux. Работа с Git-репозиторием через API, автопилот, безопасный commit без git push.

Shell 3 AI 70 Solo live ↗
FeirAI/vultrino

Credential proxy for the AI era — agents use credentials without seeing them

Rust 3 AI 70 live ↗
iuhh-sull/claude-workforce-supervisor

Permission-gated Codex skill for supervising persistent Claude Code workers.

PowerShell 2 AI 100
ArisRhiannon/vibecheck

Offline, no-AI "safe to ship?" gate for vibe-coded apps — finds the security mistakes AI coding agents make (secrets, unprotected routes, eval-RCE, SQLi, CORS, JWT, leaked keys). CLI + MCP, agent-runnable.

TypeScript 2 AI 70 Solo 1 sig live ↗
gabrielcpow0b10/homelab-agentops

Self-hosted HomeLab operations layer for monitoring, backup, recovery, automation, and future local AI agents.

Shell 2 AI 70
Renga154/agentrisk

Zero-execution preflight scanner for untrusted AI-agent and MCP artifacts

TypeScript 2 AI 70
Vadale/project-guardian

AI Guardian Firewall — a local, user-space, agent-agnostic firewall that mediates an autonomous AI agent's actions (files, shell, network, services) with a deterministic policy boundary, a tamper-evident audit log, and a human-in-the-loop approval cockpit. No kernel modules. Apache-2.0.

Rust 2 AI 70
calionauta/pi-leakguard

seatbelt for my pi.dev agent: blocks secret-file access, redacts creds from output, blocks egress + git leaks.

TypeScript 2 AI 70
ASH1998/PACT

PACT is a runtime security layer for AI agents.

Python 2 AI 70 Solo 1 sig live ↗
mthamil107/ai-bot-shield

Drop-in middleware that detects AI bot traffic. Community-maintained signature database + RFC 9421 Web Bot Auth verification. Node + Python + Go. Apache-2.0.

Python 1 AI 100
hlsitechio/claude-skills-security

Defensive security audit skills for Claude — tech-stack-keyed and audit-domain-keyed packs for SaaS apps.

Shell 1 AI 100 1 sig
gapilongo/pentest-copilot

Self-hosted pentest copilot. Substrate-first (technique catalog + playbooks + RAG + deterministic tools) with structural verifier rules and LLM-as-judge quality eval. Apache 2.0.

Python 1 AI 100 Solo live ↗
dagaada/erc20-signature-airdrop

Secure ERC20 Token Claim Contract ⚡️ | Signature-Based Distribution 2026 🔐

HTML 1 AI 100
marsley01/agent-preflight

Pre-deploy checklists for AI coding agents. Catch security holes, broken auth, and payment bugs before they hit production.

TypeScript 1 AI 100 Solo live ↗
Joaquin-web/kernel-gaze-agent

2026 Ultimate Podman AI Coding Agent – Zero-Trace, MIT Licensed GitHub Repo

HTML 1 AI 80
aguleykovn8n/security-audit-skill

Universal security audit skill for Claude Code — OWASP Top 10 (2021) + Russian security standards (ГОСТ Р 56939, ФСТЭК, ФЗ-152) + STRIDE threat modeling. Multi-stack: Node/Python/Go/Rust.

1 AI 70
tejaskembalkar-ship-it/Argus

AI-agent reliability and governance layer: auto-firing compliance checks, persistent memory, security scanning, and verification loops that wrap any AI agent.

JavaScript 1 AI 70 4 sig
rajveer100704/AgentOS

AI governance and edge infrastructure platform with HTTP/3, OpenTelemetry tracing, adaptive load shedding, circuit breakers and Kubernetes deployment support.

Go 1 AI 70 Solo live ↗
gabrielcpow0b10/homelab-agentops-control-plane

Local-first AgentOps control plane prototype for safe AI-to-agent command validation, policy evaluation, and redacted audit logging.

Python 1 AI 70
0x61A/fullstack-pro-max

13-module Claude Code skill for shipping a full web product: backend, security, SEO, ads, AI integration, analytics, email, i18n & more — stdlib-only, self-contained

Python 1 AI 70
AnYejun/blind-vault

🕶️ Secrets your AI agent can USE but never SEE — Claude Code skill + zero-dependency macOS Keychain CLI. Env injection, pointer manifest, prompt-injection tripwire.

Python 1 AI 70
lao-tseu-is-alive/Talunor

Talunor is a local-first terminal AI agent written in Go, with persistent, auditable SQLite memory, guarded tool use, and a complete step-by-step course explaining how it is built.

Go 1 AI 70 2 sig
jmac4909/Kronos

Terminal-first VS Code control plane for human-governed AI-assisted software delivery.

TypeScript 1 AI 70 1 sig
digsarab112/taskwitness

Evidence-first verification for AI coding agents — prove what changed, what was tested, and what passed.

TypeScript 1 AI 70
snowflakeovo/cmdi-command-injection

Security testing skill for OS command injection and argument injection. Claude Code skill format.

1 AI 70
thedatakey/apollyon

Source code security scanner for human-written and AI-generated projects. Rust CLI with explicit coverage, JSON/SARIF, and coding-agent integrations. Built by Tom Koentjes. Pre-alpha.

Rust 1 AI 70 4 sig
TrothByte/low-level-skills-trothbyte

Production-grade low-level engineering skills for AI coding agents. 124 verified, source-backed skills (C, C++, Rust, asm, kernel, embedded, Zig, GPU, RE, build systems) with provenance, examples, and evals.

C 1 AI 70 Solo 1 sig live ↗
korinfra/korinfra

Open-source FinOps CLI for AWS. Scans your account, finds cost and security waste, and auto-generates the Terraform fixes. Rule-based core, optional AI assist for complex patches.

TypeScript 1 AI 60 live ↗
taiman724/gh-pr-trust-scan

Evaluate AI-PR rejection risk for a GitHub repository before you fork it

Python 1 AI 60
PHPCraftdream/rust-intel

A living spec defending against the 26 categories of mistakes LLMs systematically make in Rust. Claude Code skill + 3 slash commands (rust-audit, rust-fix, rust-plan) built on a single source of truth.

JavaScript 1 AI 60

RELATED Other topics · full topics ranking →

#claude-code

1,564

#ai-agents

1,160

#llm

1,071

#claude

943

#python

806

#ai

741

#developer-tools

728

#mcp

727

#codex

521

Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology