Claude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI security, and 20+ language-specific security quirks.
Open-source AI security scanner for Codex, Claude Code, and ACP-compatible coding agents—kept current with OpenAI Codex Security.
The AI security agent guards your code.
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks
Collection of agent skills to find vulnerabilities inside your web/mobile apps.

Build Secure and Compliant AI agents and MCP Servers. YC W23
Threat modeling and AI-reasoning vulnerability detection harness for Claude Code — STRIDE + AI + MAESTRO
See how you really use AI — X-ray your AI coding sessions locally

A security scanner for your LLM agentic workflows
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Discover and compare open-source Agent Skills, tools & MCP servers — with quality scoring, trending analysis, and automated GitHub sync

OWASP Foundation web repository
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
Open-source adversary emulation for AI agents and MCP servers.

Deterministic safety solutions for probabilistic AI agents
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agents
Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
A curated corpus of incidents, attack vectors, failure modes, and defensive tools for autonomous AI agents.
A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.
Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.
Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.