#security-tools
GitHub repositories that have self-applied the topic "security-tools" — a creator-tagged metadata that surfaces how AI projects describe themselves.
REPOS Repos for #security-tools (top 14 by stars)
Reachability triage for vulnerability scans. Feeds scanner findings to an LLM agent that reads your source and decides which CVEs are actually reachable.
NovaCode37/claude-security-skillsProduction-ready Claude Code skills for cybersecurity — secret scanning, SAST, prompt-injection testing, HTTP/JWT/dependency auditing. Zero dependencies.
Actenon/actenon-scanFind where agent-controlled intent reaches consequential actions without an authority check. Python + TypeScript + Go. Zero-dependency SAST for AI agents.
zgroves24/agent-operator-skillsReusable AI-agent skills for planning, verification, security reviews, SEO audits, changelogs, CLIs, and multi-step coding loops.
aguleykovn8n/security-audit-skillUniversal security audit skill for Claude Code — OWASP Top 10 (2021) + Russian security standards (ГОСТ Р 56939, ФСТЭК, ФЗ-152) + STRIDE threat modeling. Multi-stack: Node/Python/Go/Rust.
pinalmdave/SwitchyardDetect when Claude silently falls back from Fable 5 to Opus 4.8, log it to a local tamper-evident ledger, and keep your work on the frontier model.
guorunjie/agentic-workflow-guardStatic analysis for AI automation workflows. Find prompt-injection paths, overpowered tools, and write-capable agent jobs before they run.
bylsxy/relayprobeEvidence-driven GPT-5.5 relay MITM audit console for canaries, prompt injection, tool calls, and usage anomalies.
sai-teja-girimaji/dspm-posture-simulatorLive DSPM Posture Simulator — Azure AI agent data exposure risk assessment (educational tool).
actradeck/actradeckVendor-neutral cockpit for supervising AI coding agents in real time — secret redaction, approval gates, and an append-only audit trail. A local-first sidecar + web console for Claude Code, Codex, and beyond.
itsraghul/lockwardenAudit what your npm dependency tree can execute — lifecycle scripts, binding.gyp, AI-agent hooks, IDE tasks — and answer "am I hit?" in seconds during supply-chain incidents. Local-first, zero telemetry.
Jokersystems-online/flowki-bugbounty-reconLLM-orchestrated bug bounty recon pipeline (Claude Code + amass/subfinder/httpx/nuclei) — companion repo to the FlowKI Club article
EvilFreelancer/secsSECS (SECurity aSsistant) turns an AI coding agent (Claude Code, Cursor, Codex) into an authorized information-security assistant - 35 security Agent Skills, a Debian/Ubuntu/Kali toolchain installer, and a local Metasploitable 3 practice lab, under strict rules of engagement.
avgoai/aos-workflow-gateGitHub Action + CLI for replayable CI/PR/release gate decisions - zero-config Self-Test turning checks, scanners, and AI-agent signals into deterministic, tamper-evident PASS/WARN/BLOCK records. Read-only, zero dependencies, Apache-2.0.
RELATED Other topics · full topics ranking →
#claude-code
1,555#ai-agents
1,156#llm
1,066#claude
936#python
802#ai
737#developer-tools
723#mcp
719#codex
517Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology