Security middleware
-
action-pin-check
Audit GitHub Actions workflows for mutable or missing action pins.
-
agent-bom
AI supply-chain & cloud security scanner and self-hosted control plane — agents, MCP, packages, cloud estate, non-human identities, and LLM cost. SBOM/SARIF, graph attack-paths, runtime enforcement, and compliance evidence.
-
agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
-
agentgate
ai security cli developer-tools agent firewall policy-as-code python anthropic claude-code
-
AI-Security-Platform
Control plane for enterprise AI security: inline runtime guardrails, automated red teaming with auto-remediation, AI asset posture (AI-SPM), and compliance governance. Python control plane + Go inline agent.
-
aicheck-scan
Fail the build if your PR ships an exposed self-hosted AI service. Live-probes Ollama, n8n, vLLM, Langfuse, Open WebUI and 12 more — graded A–F report, fix-card links, SARIF code scanning.
-
aileron
Tamper-evident flight recorder for AI agents - hash-chained, signed audit log of every tool call, with MCP proxy policy enforcement and anomaly detection.
-
aishield
🛡️ Agent-native AI tool security scanner. Scan MCP/Skill/GPT/Prompt for security risks. 4-dimensional scoring. Certified badges. Guardrail MCP for auto-protection.
-
Aivist-Verify
A BOLA/IDOR access-control confirmation engine — code adjudicates every verdict, not just the model, with a reproducible evidence chain.
-
android-agent
Control Android devices through ADB with this Python automation framework for task execution and phone farm scaling.
-
antivirus-yara-rules
fully equip AV Desktop App
-
arka
Natural-language AI agent for your terminal — 70+ skills, voice, multi-provider LLM failover, and system automation.
-
AttackMap
AI-assisted defensive security analysis for codebases.
-
attestral
Open-source security scanner for MCP servers and AI agents: finds prompt injection, tool poisoning, and excessive agency, and models the cloud your agents can reach. pip install attestral.
-
authgent
Open-source MCP-OAuth conformance scanner + IETF reference implementation of draft-ietf-oauth-identity-chaining-14 and draft-ietf-oauth-transaction-tokens-08. CLI + GitHub Action + hosted scanner + public registry. Apache 2.0.
-
AutoPassCrack
🔑 Automate brute-forcing web login forms with ease. Enjoy flexible options like custom generation and advanced field detection for efficient password cracking.
-
AWSBestPracticesSkill
Unofficial source-linked AWS best practices for every AWS service, organized by Well-Architected pillar for Claude Code, OpenAI Codex, and AI coding agents.
-
AZL-Truth
Universal Operating Logic For Anything That Understands It - Via Infinite Mapping with the Casteelian Coordinate & Count
-
Casbin
Authorization library supporting access-control models like ACL, RBAC, and ABAC.
-
cavra
CAVRA - Controlled Agentic Verification & Runtime Authority. Before the agent acts, CAVRA decides. CAVRA is a runtime governance and authority layer for AI coding agents.
-
CiberWebScan
Hybrid tool for passive reconnaissance and attack surface analysis in web applications. It combines advanced scraping, technology fingerprinting, security assessment, and reporting into a single CLI solution. Designed for ethical, educational, and auditing purposes. This software MUST NOT be used on third-party systems.
-
clawseccheck
🦞 Free, local, read-only security self-audit for your own OpenClaw AI-agent setup. Scores it A–F, surfaces the urgent holes, emits copy-paste fixes. Zero deps, no network, no API key — your data never leaves your machine.
-
cloud-ai-security-skills
Cloud and AI security automation skills: OCSF-shaped evidence, detection engineering, audit, compliance, MCP workflows, and HITL-controlled operations.
-
contextduty
Policy-driven context firewall for AI workflows — redact secrets and PII before prompts leave your machine
-
copyleftdev
Systems-level software engineer building security tools, developer infrastructure, and AI-native systems in Rust, Go, and Zig. 560+ open source repositories.
-
crewscore
Find the safety rules your AI agent prompt forgot. Checks 23 published controls — injection defense, human approval, cost limits, stop conditions. Offline CLI + GitHub Action + in-browser checker. No API key, no LLM.
-
freebsd-industrial-edge-ai-secure-device
Demonstrate secure FreeBSD ARM64 edge AI devices that collect telemetry and run embedded AI with containerized data science and real-time ML pipelines.
-
gecko-surf
The knowledge graph for APIs your agent can trust. Maps any API — even messy, paywalled, or on-chain ones — into a verified graph your agent traverses instead of guessing, and simulates any action to a receipt before money moves.
-
gh-safe-repo
Python CLI that creates GitHub repos with safe defaults — branch protection, Dependabot, secret scanning, and pre-flight security scanning — applied automatically.
-
hexgraph
Self-hosted, agentic vulnerability research for binaries & firmware: an AI agent decompiles, fuzzes, and verifies exploits inside a sandbox, recording every finding to a typed graph. BYOK, fully local.
-
job-hunter
Automated job scraping pipeline for security engineer roles. Python + GitHub Actions + Gemini API.
-
linkedin-easyapply-antidetection-bot
Automate LinkedIn Easy Apply with stealth browser techniques and AI-driven form filling to test anti-detection and security research methods.
-
LLM_Gateway
Self-hosted LLM gateway with security, audit, and policy enforcement for on-prem AI deployments
-
mcp-krb-server
Kerberos/SPNEGO single sign-on for MCP servers in FreeIPA environments. Provisioning framework for Windows (via WSL), Linux and macOS development environments.
-
mcp-safeguard
🛡️ Automated security scanner for MCP (Model Context Protocol) servers — 52 rules for prompt injection, credential exposure, SSRF & tool poisoning. pip install mcp-safeguard
-
noai-watermark
Remove invisible AI watermarks and manage metadata from images generated by popular AI models like DALL-E, Midjourney, and Stable Diffusion.
-
nuguard
AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.
-
obsidianvault
Encrypt and share files with zero-knowledge, browser-based AES-256-GCM transfer that keeps keys in the URL fragment and data off the server
-
OcyShield-Framework
Audit Android systems with this modular framework for security testing, payload deployment, and session management.
-
purrsh3ll
AI-powered terminal environment for penetration testers
-
QQgroup-annual-report-analyzer
📊 Analyze QQ group chat records to create stunning annual reports with customizable features and AI integration for enhanced insights.
-
quodeq
AI-powered code quality and security scanner. Open source, MIT, runs locally. <🧭>
-
raztint
Secure, consistent terminal output for Python CLIs with semantic messages, icons, and secret redaction.
-
recon
Public-metadata domain intelligence from DNS, certificate transparency, and unauthenticated identity discovery. Local Python CLI, versioned JSON, and stdio MCP server. No credentials or active scanning.
-
red-team-blue-team-agent-fabric
AI agent security harness for adversarial testing: 606 executable tests on main, 603 in the v4.15.0 release, across MCP, A2A, x402/L402, decision governance, benchmark integrity, human-in-the-loop, skill supply chain. Commit-pinned OWASP Agentic v1.1 T1-T17 (13 direct, 4 partial), AIUC-1 2026-Q1/Q2 crosswalk 19/20, NIST AI 800-2 aligned.
-
runbookproof
Continuously verify commands in documentation, runbooks, and AI-generated instructions.
-
SassyMCP
One MCP server, 270 tools, replaces 75+ — files, shell, GitHub, Android, desktop vision, security & forensics, persistent memory. Smart context-saving tool loading, safe-delete guardrails, and an orphan-proof self-healing process supervisor. Works with Claude Desktop, Cursor, Windsurf, and any MCP client.
-
Secure-Agent-Launcher
Block AI agent access to sensitive macOS paths and log all actions to protect private data during command execution.
-
security-playbooks
Explore open-source ATT&CK scenarios, detection rules, and blue-team labs for hands-on security testing
-
syslogcef
Python package and CLI to convert syslog (RFC3164/RFC5424, rsyslog, journald) into ArcSight CEF, with mappings for Cisco ASA/IOS, F5, Linux, and VMware
-
TrashDroid
Automate comprehensive Android app security testing with TrashDroid using adb, drozer, and apktool for a full nine-phase dynamic analysis.
-
trusca
Self-hosted, open-source SCA portal — vulnerability (CVE), license compliance, and SBOM management in one UI. Black Duck/Snyk-class capabilities, Apache-2.0.
-
trustsight
AUR package update vetting tool. Run it before yay -Syu.
-
vigil-tui
Monitor real-time power consumption, thermals, and clock speeds for CPU, GPU, and RAM directly in your terminal.
-
VoiceGuard
🔒 Enhance security with VoiceGuard, an AI-driven voice authentication system powered by OpenAI’s ChatGPT and Whisper for reliable voice identification.
-
webscan
Automated CLI security auditor for web configuration vulnerabilities.
-
Yana-AI
Personal Agent OS. Deterministic runtime guardrails for AI agents with hooks, policy engine, audit logs, and multi-agent orchestration. Apache 2.0 License
-
ZugaShield
7-layer AI agent security system — stop prompt injection, data exfiltration, and AI-specific attacks in under 15ms. Zero dependencies.
-
zWorkforce
Enterprise AI Workforce Operating System — distributed control plane, durable agents, workflow automation, governance, MCP integration and AI FinOps. zWorkforce turns one or more LLM endpoints into a governed AI workforce. A tenant dispatches work to named agents; a cost-aware Luna/Terra/Sol
-
zzyCaptcha
🛡️ Generate secure, animated GIF CAPTCHAs with zzyCaptcha, a self-hostable service designed for easy integration and effective bot protection.
Security Python -
GitHub-Cyber-Scanner-Pro