AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
Open-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.

Ghost Security's collection of AppSec skills for AI coding agents
Agent Skill for PHP security audits - OWASP patterns, vulnerability detection | Claude Code compatible
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.
A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Security testing that runs inside the coding agent you already use. Source-available, not open source.
Security testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties

Deterministic safety solutions for probabilistic AI agents
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
Blackhat 2025 presentation and codebase: AI SOC agent & MCP server for automated security investigation, alert triage, and incident response. Integrates with ELK, IRIS, and other platforms.
Multi-tier framework for evaluating AI agent skills with quality gates, semantic overlap detection, synthetic evaluation dataset generation, and live agent evaluation that measures how skills affect agent behavior.
A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, in the browser, or in the cloud.
Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt injection, supply chain etc in a local dashboard. Agent agnostic (Claude, codex, langchain etc.)