Go · npm83Excellenthealth index
xalgord/xalgorixAutonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Go · TypeScript★ 768Jul 17, 2026
PyPI81Excellenthealth index
depalmar/ai_for_the_winBuild AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red teaming. Includes Colab notebooks, Docker environment, and CTF challenges.
Python · Jupyter Notebook★ 157Aug 4, 2026
C · Swift★ 6,171Aug 28, 2026
crates.io · npm77Goodhealth index
backbay-labs/clawdstrikeAI EDR for developer workstations and autonomous agent fleets. Build Swarm Detection & Response platforms with Clawdstrike.
TypeScript · Rust★ 285Aug 4, 2026
Python · JavaScript★ 1,093↓ 188/moJul 17, 2026
Python★ 67↓ 836/moJul 17, 2026
Go · Maven77Goodhealth index
seqra/seqraThe open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 110Jul 17, 2026
RAJANAGORI/NightingaleNightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes preconfigured with all essential tools and utilities required for efficient Vulnerability Assessment and Penetration Testing (VAPT), streamlining the setup process for security professionals.
Dockerfile · Shell · Python★ 313Aug 4, 2026

Shuffle/ShuffleShuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
JavaScript · Shell★ 2,423Aug 31, 2026

panguard-ai/panguard-aiOpen-source security platform for AI agents -- audits skills before install, monitors 24/7, shares threat intelligence across all users. | AI Agent 開源安全平台 -- 安裝前審計 skill、24/7 即時監控、社群共享威脅情報。
TypeScript★ 63↓ 1,214/moSep 5, 2026
Go · npm73Goodhealth index
Go · TypeScript★ 14Jul 23, 2026
PyPI · npm71Goodhealth index
PrismorSec/prismorRuntime Firewall for AI agents which catches the rogue tool call before it runs. Dangerous commands, secret leaks, prompt injection. For Claude Code, Codex and framework SDKs
Python · HTML★ 240↓ 6,171/moJul 19, 2026
TypeScript★ 9↓ 15K/moSep 5, 2026
PyPI · npm71Goodhealth index

vaquarkhan/MCP-BastionMCP-Bastion: The Zero-Infrastructure Runtime Middleware ,Enterprise-Grade Security Middleware for the Model Context Protocol (MCP)
Python★ 4↓ 3,959/moAug 16, 2026

Drakon-Systems-Ltd/ShieldCortex🧠🛡️ Complete memory & security for AI agents. Persistent storage, semantic search, prompt injection firewall, audit trail. One package.
TypeScript★ 25↓ 14.6K/moAug 22, 2026

KryptSec/oasisOpen-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.
TypeScript★ 29↓ 39/moAug 28, 2026
npm · PyPI69Goodhealth index
TypeScript · JavaScript · Python★ 1↓ 537/moJul 21, 2026

mukul975/Anthropic-Cybersecurity-Skills817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Python★ 27.3KAug 5, 2026
Python★ 23↓ 752/moJul 26, 2026

cc1a2b/JShunterjshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for and bug bounty hunters and security researchers.
Go★ 533Sep 6, 2026

djadmin/fortAudit and fix your Mac's security in one command. No agent, no signup, open source.
Go · HTML★ 78Sep 5, 2026
Go · npm63Moderatehealth index
cyberspacesec/har-skillsHAR Skills — AI-native library for HAR file analysis. Access via: Skills (CLAUDE.md), Go SDK, CLI, MCP. 23 commands, 70+ methods, progressive disclosure docs.
Go★ 29Aug 3, 2026
famclaw/honeybadgerSecurity scanner for AI agent skills and MCP servers. Detects secrets, CVEs, supply chain attacks, and prompt injection in SKILL.md files before they're installed. Pre-install gate for Claude Code, OpenClaw, PicoClaw, NanoBot, FamClaw, and CI/CD pipelines. Single Go binary, MIT licensed.
Go★ 3Jul 17, 2026
PyPI63Moderatehealth index
manthanghasadiya/mcpsecAn AI-driven dynamic protocol fuzzer for the Model Context Protocol (MCP). Prove runtime exploitability by discovering state violations, transport crashes, and application-layer logic flaws (SSRF, LFI) before your AI agents do.
Python★ 22↓ 319/moJul 28, 2026
PyPI62Moderatehealth index
3xp0rt/NaminterA Python package and command-line interface (CLI) tool for asynchronous OSINT username enumeration using the WhatsMyName dataset
Python★ 43↓ 733/moJul 18, 2026
npm62Moderatehealth index

Hyperyond/HoverOpen-source Vibe Testing suite: an MCP server for the coding agent you already run, a VS Code review cockpit, and CI. Your agent explores your app and crystallizes each flow into a plain @playwright/test spec you own — record == replay, runs in CI with zero AI.
TypeScript★ 11↓ 742/moSep 5, 2026
Go · npm62Moderatehealth index
scagogogo/cwe-skillsAI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 3Jul 19, 2026
PyPI62Moderatehealth index
Python★ 4↓ 2,911/moAug 18, 2026
HCL · PowerShell★ 38Aug 4, 2026
PyPI60Moderatehealth index
Python★ 23Jul 19, 2026