Trending Security Repos
1 Oldcircle/geo‑sleuth An agent skill that finds where a photo was taken — OpenStreetMap geometry, elevation skylines, satellite imagery and street view — and shows its work. Works with Claude Code, Codex, Cursor, Gemini CLI, OpenCode and GitHub Copilot. | 1.6k +75/day | +972 in 7d | 163 | 21d ago | Python |
2 openqodex/openqodex Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed, then a separate reviewer process that checks every scanner finding and is given every changed line. No other API key. | 516 +74/day | +516 in 7d | 34 | 7d ago | TypeScript |
3 mdpsec/bug‑bounty‑hunting‑prompts Reusable prompts for a structured, evidence-first bug bounty hunting workflow | 521 +58/day | +383 in 7d | 115 | 9d ago | |
4 Sequester-AG/bug‑bounty‑triage Agent skill for rigorous bug bounty report triage, validation, severity escalation, and submission-ready reporting. | 46 +46/day | 8 | 1d ago | ||
5 strands-agents/box Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support planned. | 296 +42/day | +295 in 7d | 12 | 7d ago | Rust |
6 nealbridges/VulnHunter Agentic AI security scanner that hunts exploitable vulnerabilities like an adversary, proves them with executable PoCs, and fixes them test-first. A maintained fork of Capital One's VulnHunter, rebuilt for any agent harness. | 678 +40/day | +680 in 7d | 105 | 17d ago | Python |
7 aixisstudio/Snitch Real-time network traffic visualizer — see every connection your computer makes. Privacy-first, 100% local. / Visualiseur de trafic réseau en temps réel, 100% local. | 194 +24/day | +187 in 7d | 14 | 8d ago | Python |
527 +19/day | +39 in 7d | 193 | 28d ago | JavaScript | |
9 shinthink/blitzstrike Blitz Strike — a universal MCP security-audit toolbelt. Reconnaissance at speed. Analysis in depth. Validation before report. | 503 +19/day | +7 in 7d | 6 | 27d ago | TypeScript |
10 Blackfrost-AI/Cyber‑Frost‑Harness Native red, blue, and purple security-agent harness for CYBER-FROST | 50 +13/day | +50 in 7d | 7 | 4d ago | Python |
11 devZero-Security/redStackPRO A canvas for red team infrastructure and cyber ranges. Compose a topology, export runnable Terraform and Ansible, and deploy it yourself. Your cloud credentials never leave your machine. | 141 +10/day | +8 in 7d | 16 | 14d ago | Python |
12 socai-io/jev‑social Open-source, local-first social media research agent for Instagram, TikTok, and LinkedIn. Jev routes read-only steps; socai CLI captures cited browser evidence. | 158 +8/day | +16 in 7d | 35 | 21d ago | JavaScript |
13 brandynfisher/ToolReplay Audit AI agent tool-call transcripts: hash-chain sealing, deterministic replay, and scope overreach checks. Dependency-free Python CLI. | 184 +7/day | 21 | 25d ago | Python | |
14 velvet-semicolon/action‑dist‑verify Rebuild the JavaScript GitHub Actions your workflows pin and check that their committed dist matches the source. | 69 +6/day | 10 | 11d ago | TypeScript | |
56 +6/day | +10 in 7d | 6 | 10d ago | JavaScript | |
16 CassiopeiaCode/CosyRedactGateway Lightweight, stateless privacy gateway for LLM APIs — redact secrets before OpenAI/Anthropic upstreams and restore them transparently in SSE and tool calls. | 100 +4/day | +2 in 7d | 24 | 28d ago | JavaScript |
17 7wp81x/NRSuite‑Android No-root Android + ESP32 Wi-Fi/BLE security testing toolkit. Deauth, captive portal, packet capture, BLE HID, and defense/detection modules, controlled over USB-OTG, no custom kernel or external adapter required. | 102 +4/day | +39 in 7d | 13 | 24d ago | Kotlin |
18 DeathShotXD/Comment2Shell Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post and drops a self deleting webshell. Full chain PoC with scanner interactive shell Nuclei template and Docker | 63 +4/day | +2 in 7d | 15 | 15d ago | Python |
19 leepokai/jev‑guard Auto mode for every coding agent, built on Jev: risk-scores every tool call with session context (deny / ask / allow), flags prompt injection in results, checks skills and plugins. Claude Code, Codex, Copilot, Gemini, Cursor, pi, OpenCode, ACP. | 63 +3/day | +7 in 7d | 10 | 22d ago | JavaScript |
20 Mister-iks/pcybox‑attackgraph Open source browser lab to build a simulated infrastructure, watch an attack move through it, and check whether your defense works. | 46 +3/day | +2 in 7d | 8 | 14d ago | TypeScript |
30 +3/day | +5 in 7d | 5 | 10d ago | Zig | |
22 cn0xroot/CC‑Monitor Claude Code Monitor : Monitor & audit every action Claude Code takes on your computer. | 65 +2/day | +3 in 7d | 9 | 27d ago | JavaScript |
23 Ethan-Andrews/ThreatIntel‑Aggregator Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs standalone or fully Azure-integrated. | 59 +2/day | +3 in 7d | 7 | 25d ago | Python |
24 Justinuse1/pojia‑breaker Chinese-first LLM jailbreak benchmark & red-team toolkit | 中文LLM安全评测框架 | by POJIA.AI | 33 +2/day | +6 in 7d | 5 | 16d ago | JavaScript |
37 +2/day | +5 in 7d | 6 | 21d ago | ||
26 CodeByPinar/riskops BT ve siber güvenlik risk yönetimi platformu — risk envanteri, 5×5 değerlendirme, aksiyon takibi ve kurumsal raporlama. PHP 8.3 + MariaDB, framework ve CDN kullanmadan. | 32 +1/day | +1 in 7d | 10 | 28d ago | PHP |
27 grepleaks/grepleaks Grepleaks — your AI pentest environment. An AI pentest agent that lives in your terminal. | 29 +1/day | +16 in 7d | 6 | 23d ago | TypeScript |
28 shaikarifali/bundlebleed AI/LLM-assisted JS Recon and vulnerability triage for authorized bug bounty testing & pentesting — scope-gated, passive-by-default, human-verified | 34 +1/day | +0 in 7d | 8 | 26d ago | Python |
29 laoshu666/hermes‑seagull 🦅 Seagull Profile - Unrestricted CTF/Red-team AI personality for Hermes Agent | 海鸥破甲人格 | 39 +1/day | +8 in 7d | 14 | 28d ago | PowerShell |
30 security-attack/RingKiller RingKiller — BYOD PoC for vulnerable driver DCRCVDrv.sys. Abuses IOCTL 0x2205C0 to kill arbitrary processes from ring 0 via ZwTerminateProcess. EDR/AV termination primitive. Lab only. | 26 +1/day | +1 in 7d | 6 | 27d ago | C |