MCP Server Security Standard (MSSS): an open, testable security control standard for certifying MCP servers, with levels, evidence requirements, and reporting schemas.
Comprehensive sets of standards and practices designed to elevate the capabilities of AI coding agents.
Find and repair substance defects in AI-assisted prose, code, docs, and agent output. Reports defects, never authorship. Structural tests over model judgement, because LLM judges agree with human slop labels at chance.
Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks

MCP configuration to connect AI agent to a Linux machine.
An instruction layer for AI coding agent
Type one sentence, approve once, walk away — Toh Framework installs an AI build department (14 commands, 8 agents, 23 skills) into your project and keeps building, testing and fixing until it is verified done. Works in Claude Code, Cursor, Antigravity, Codex and ZCode.

Build Secure and Compliant AI agents and MCP Servers. YC W23
90 specialist AI agents + 3 project-local extensions for Claude Code / Codex CLI / Antigravity CLI (agy). Anthropic Agent Skills spec-aligned, hub-spoke orchestration via Nexus with 49 Recipes and 11 Skill Packs. Covers development, security, design, testing, FinOps, compliance, observability, and AI/ML.
Fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and enhance your hacking toolkit!
AI-powered bug bounty hunting toolkit that works with or without subscription.
AI plugin to enhance and accelerate Flutter & Dart development, built by Very Good Ventures
Open-source adversary emulation for AI agents and MCP servers.
My profile & the agent skills I created
A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com
Master Claude Code Hooks
Agent Skills for traceable requirements, independent verification, human approval gates, and auditable AI-assisted engineering. Supports Claude Code, Cursor, VS Code, and GitHub Copilot; ISO 9001/27001 aligned (design phase), GxP-aware.

Ghost Security's collection of AppSec skills for AI coding agents
Claude Code role-based Rails agent kit with orchestrator and specialist slash commands.
Code Execution Sandbox Platform Solution for Individuals and Small Teams with MCP
A command-line interface for interacting with MCP (Model Context Protocol) servers using both stdio and HTTP transport.
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
The AI toolkit for building reliable browser automations