#security
GitHub repositories that have self-applied the topic "security" — a creator-tagged metadata that surfaces how AI projects describe themselves.
REPOS Repos for #security (top 40 by stars)
实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun 案例统计
ByteRay-AI/XpsdReachability triage for vulnerability scans. Feeds scanner findings to an LLM agent that reads your source and decides which CVEs are actually reachable.
RefuseHQ/refuseOpen-source server that refuses vulnerable package installs. The backend the refuse CLI shim calls.
AppThreat/chennaichennai (chen N ai) is a hybrid AI agent and a terminal user interface for static analysis, data-flow tracing, and AI-assisted code and security analysis.
proluct/skannaSecurity scanner for Claude Code skills, plugins, and MCP servers. A verdict before you install.
ralfyishere/agent-zero-trustZero-trust repo intake for AI coding agents — scan the instruction environment before Claude Code, Cursor, Codex, or Gemini touches a repo. Ships its own false-negative ledger.
decksoftware/csreviewDevelopment-time local workspace security alignment for AI coding agents
Actenon/actenon-scanFind where agent-controlled intent reaches consequential actions without an authority check. Python + TypeScript + Go. Zero-dependency SAST for AI agents.
5uprem4/ai-skill-vaultMaster AI Skills Collection 2026 - Scalable Agent Scripts & Automation Hub
hannsxpeter/ready-suiteTen composable AI skills covering the full arc from idea to launch. Discovery hub for prd-ready, architecture-ready, roadmap-ready, stack-ready, repo-ready, production-ready, deploy-ready, observe-ready, launch-ready, harden-ready. Plug into Claude Code, Codex, Cursor, Windsurf.
Yahor777/repopilot-bridge🔒 Кросс-платформенный локальный мост для AI coding agents: Windows, macOS и Linux. Работа с Git-репозиторием через API, автопилот, безопасный commit без git push.
FeirAI/vultrinoCredential proxy for the AI era — agents use credentials without seeing them
iuhh-sull/claude-workforce-supervisorPermission-gated Codex skill for supervising persistent Claude Code workers.
ArisRhiannon/vibecheckOffline, no-AI "safe to ship?" gate for vibe-coded apps — finds the security mistakes AI coding agents make (secrets, unprotected routes, eval-RCE, SQLi, CORS, JWT, leaked keys). CLI + MCP, agent-runnable.
gabrielcpow0b10/homelab-agentopsSelf-hosted HomeLab operations layer for monitoring, backup, recovery, automation, and future local AI agents.
Renga154/agentriskZero-execution preflight scanner for untrusted AI-agent and MCP artifacts
Vadale/project-guardianAI Guardian Firewall — a local, user-space, agent-agnostic firewall that mediates an autonomous AI agent's actions (files, shell, network, services) with a deterministic policy boundary, a tamper-evident audit log, and a human-in-the-loop approval cockpit. No kernel modules. Apache-2.0.
calionauta/pi-leakguardseatbelt for my pi.dev agent: blocks secret-file access, redacts creds from output, blocks egress + git leaks.
ASH1998/PACTPACT is a runtime security layer for AI agents.
mthamil107/ai-bot-shieldDrop-in middleware that detects AI bot traffic. Community-maintained signature database + RFC 9421 Web Bot Auth verification. Node + Python + Go. Apache-2.0.
hlsitechio/claude-skills-securityDefensive security audit skills for Claude — tech-stack-keyed and audit-domain-keyed packs for SaaS apps.
gapilongo/pentest-copilotSelf-hosted pentest copilot. Substrate-first (technique catalog + playbooks + RAG + deterministic tools) with structural verifier rules and LLM-as-judge quality eval. Apache 2.0.
dagaada/erc20-signature-airdropSecure ERC20 Token Claim Contract ⚡️ | Signature-Based Distribution 2026 🔐
marsley01/agent-preflightPre-deploy checklists for AI coding agents. Catch security holes, broken auth, and payment bugs before they hit production.
Joaquin-web/kernel-gaze-agent2026 Ultimate Podman AI Coding Agent – Zero-Trace, MIT Licensed GitHub Repo
aguleykovn8n/security-audit-skillUniversal security audit skill for Claude Code — OWASP Top 10 (2021) + Russian security standards (ГОСТ Р 56939, ФСТЭК, ФЗ-152) + STRIDE threat modeling. Multi-stack: Node/Python/Go/Rust.
tejaskembalkar-ship-it/ArgusAI-agent reliability and governance layer: auto-firing compliance checks, persistent memory, security scanning, and verification loops that wrap any AI agent.
rajveer100704/AgentOSAI governance and edge infrastructure platform with HTTP/3, OpenTelemetry tracing, adaptive load shedding, circuit breakers and Kubernetes deployment support.
gabrielcpow0b10/homelab-agentops-control-planeLocal-first AgentOps control plane prototype for safe AI-to-agent command validation, policy evaluation, and redacted audit logging.
0x61A/fullstack-pro-max13-module Claude Code skill for shipping a full web product: backend, security, SEO, ads, AI integration, analytics, email, i18n & more — stdlib-only, self-contained
AnYejun/blind-vault🕶️ Secrets your AI agent can USE but never SEE — Claude Code skill + zero-dependency macOS Keychain CLI. Env injection, pointer manifest, prompt-injection tripwire.
lao-tseu-is-alive/TalunorTalunor is a local-first terminal AI agent written in Go, with persistent, auditable SQLite memory, guarded tool use, and a complete step-by-step course explaining how it is built.
jmac4909/KronosTerminal-first VS Code control plane for human-governed AI-assisted software delivery.
digsarab112/taskwitnessEvidence-first verification for AI coding agents — prove what changed, what was tested, and what passed.
snowflakeovo/cmdi-command-injectionSecurity testing skill for OS command injection and argument injection. Claude Code skill format.
thedatakey/apollyonSource code security scanner for human-written and AI-generated projects. Rust CLI with explicit coverage, JSON/SARIF, and coding-agent integrations. Built by Tom Koentjes. Pre-alpha.
TrothByte/low-level-skills-trothbyteProduction-grade low-level engineering skills for AI coding agents. 124 verified, source-backed skills (C, C++, Rust, asm, kernel, embedded, Zig, GPU, RE, build systems) with provenance, examples, and evals.
korinfra/korinfraOpen-source FinOps CLI for AWS. Scans your account, finds cost and security waste, and auto-generates the Terraform fixes. Rule-based core, optional AI assist for complex patches.
taiman724/gh-pr-trust-scanEvaluate AI-PR rejection risk for a GitHub repository before you fork it
PHPCraftdream/rust-intelA living spec defending against the 26 categories of mistakes LLMs systematically make in Rust. Claude Code skill + 3 slash commands (rust-audit, rust-fix, rust-plan) built on a single source of truth.
RELATED Other topics · full topics ranking →
#claude-code
1,564#ai-agents
1,160#llm
1,071#claude
943#python
806#ai
741#developer-tools
728#mcp
727#codex
521Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology