An open API service indexing awesome lists of open source software.

awesome-ai-security

A collection of awesome resources related AI security
https://github.com/ottosulin/awesome-ai-security

Last synced: 15 days ago
JSON representation

  • Agentic AI Security Skills

    • Data & Supply Chain Security

      • tm_skills - _Agent skills to help with Continuous Threat Modeling_
      • Trail of Bits Skills Marketplace - _Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows_
      • Ghost Security Skills - _Agent application security (appsec) skills and tools for Claude Code_
      • Semgrep Skills - _Official Semgrep skills for Claude Code and other AI coding assistants. Provides security scanning, code analysis, and vulnerability detection capabilities directly in your AI-assisted development workflow._
      • claude-bug-bounty - _Claude Code skill for AI-assisted bug bounty hunting. Automates reconnaissance, IDOR, XSS, SSRF, OAuth, GraphQL, and LLM injection testing with 4-gate validation checklist and report generation._
      • Anthropic Cybersecurity Skills - _734+ structured cybersecurity skills for AI agents. MITRE ATT&CK mapped, agentskills.io standard. Compatible with Claude Code, Copilot, Codex CLI, Cursor, and Gemini CLI._
      • Elastic Agent Skills - _Collection of skills for Elastic's AI assistant, enabling natural language security investigations across logs, traces, and threat intelligence_
      • llm-sast-scanner - _SAST skill for AI coding agents (Claude Code, Codex, etc.) with structured vulnerability detection across 34 classes. Features source-to-sink taint analysis, Judge verification for false positive reduction, and 99%+ precision/recall on benchmarks._
      • sast-skills - _Collection of agent skills that turn your AI coder into a SAST scanner_
      • pentest-ai-agents - _31 Claude Code subagents for offensive security. Specialized AI subagents for recon, web, AD, cloud, mobile, wireless, social engineering, payload crafting, reverse engineering, exploit chaining, detection engineering, forensics, and report generation. Tier 2 agents can execute tools directly with approval gates._
      • Mantis Skills - _Google's decoupled, sequential, security-focused pipeline of agentic AI skills for autonomously reviewing, deduplicating, validating, reproducing, and patching vulnerabilities across codebases of any scale. Features a multi-stage pipeline (architecture analysis → threat modeling → research → review → reproduction → patching → calibration → reflection), built-in sandboxing, and a continuous learning loop that adapts across iterative runs. Supports RTL hardware, IaC, ML pipelines, and compiled binaries._
      • USAP - _80 cybersecurity skills + 13 orchestrator agents with a typed 11-field output contract, an enforced resolvable-evidence gate (no verdict without a resolvable source), connector-agnostic MCP routing to downstream security tools, and human-approval gating for every mutating action. MITRE ATT&CK + NIST CSF 2.0 mapped. Runs in Claude Code, Cursor, Codex, and Gemini._
      • reverse-skill - _Cybersecurity skill router for AI coding clients (Claude Code, Codex, Cursor, OpenCode). Routes APK/binary/JS reverse engineering, pentest, malware, CTF, and firmware tasks to the right methodology with 43 routing rules, on-demand toolchain bootstrap, and a 173-case routing benchmark._
  • Attack Techniques & Red Teaming

    • Adversarial ML & Classical Models

      • awesome-ai-safety
      • Malware Env for OpenAI Gym - _makes it possible to write agents that learn to manipulate PE files (e.g., malware) to achieve some objective (e.g., bypass AV) based on a reward provided by taking specific manipulation actions_
      • Deep-pwning - _a lightweight framework for experimenting with machine learning models with the goal of evaluating their robustness against a motivated adversary_
      • Counterfit - _generic automation layer for assessing the security of machine learning systems_
      • DeepFool - _A simple and accurate method to fool deep neural networks_
      • Snaike-MLFlow - _MLflow red team toolsuite_
      • Charcuterie - _code execution techniques for ML or ML adjacent libraries_
      • Exploring the Space of Adversarial Images
      • BadDiffusion - _Official repo to reproduce the paper "How to Backdoor Diffusion Models?" published at CVPR 2023_
      • Adversarial Robustness Toolkit - _ART focuses on the threats of Evasion (change the model behavior with input modifications), Poisoning (control a model with training data modifications), Extraction (steal a model through queries) and Inference (attack the privacy of the training data)_
      • cleverhans - _An adversarial example library for constructing attacks, building defenses, and benchmarking both_
      • foolbox - _A Python toolbox to create adversarial examples that fool neural networks in PyTorch, TensorFlow, and JAX_
      • TextAttack - _A Python framework for adversarial attacks, data augmentation, and model training in NLP_
      • secml-torch - _SecML-Torch: A Library for Robustness Evaluation of Deep Learning Models_
      • Adversarial Machine Learning Library (Ad-lib) - _Game-theoretic adversarial machine learning library providing a set of learner and adversary modules_
      • OffsecML Playbook - _A collection of offensive and adversarial TTPs with proofs of concept_
    • Agentic AI & MCP Attack Tools

      • OpenPromptInjection - _A benchmark for prompt injection attacks and defenses_
      • mcp-injection-experiments - _Code snippets to reproduce MCP tool poisoning attacks._
      • RAMPART - _pytest-native safety and security testing framework for agentic AI applications._
      • AIMap - _Internet-scale discovery and security testing platform for exposed AI agent infrastructure. Queries Shodan for MCP servers, Ollama instances, vLLM/LiteLLM proxies, and more — then fingerprints, scores risk, and launches protocol-specific attack suites with real-time streaming results._
      • AI-Infra-Guard - _A comprehensive, intelligent, and easy-to-use AI Red Teaming platform developed by Tencent Zhuque Lab. Integrates modules for Infra Scan, MCP Scan, and Jailbreak Evaluation, providing a one-click web UI, REST APIs, and Docker-based deployment for comprehensive AI security evaluation._
    • AI-Assisted Offensive Security

      • HackGPT - _A tool using ChatGPT for hacking_
      • mcp-for-security - _A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. Integrate security testing and penetration testing into AI workflows._
      • cai - _Cybersecurity AI (CAI), an open Bug Bounty-ready Artificial Intelligence ([paper](https://arxiv.org/pdf/2504.06017))_
      • PentestGPT - _A GPT-empowered penetration testing tool_
      • HackingBuddyGPT - _Helping Ethical Hackers use LLMs in 50 Lines of Code or less_
      • HexStrikeAI - _HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research._
      • Burp MCP Server - _MCP Server for Burp_
      • burpgpt - _A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type._
      • guardian-cli - _AI-Powered Security Testing & Vulnerability Scanner. Guardian CLI is an intelligent security testing tool that leverages AI to automate penetration testing, vulnerability assessment, and security auditing._
      • strix - _Strix are autonomous AI agents that act just like real hackers - they run your code dynamically, find vulnerabilities, and validate them through actual proof-of-concepts_
      • mcp-security-hub - _A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more._
      • AutoPentestX - _AutoPentestX – Linux Automated Pentesting & Vulnerability Reporting Tool_
      • CyberStrikeAI - _AI-native security testing platform built in Go. Integrates 100+ security tools with an intelligent orchestration engine, role-based testing with predefined security roles, skills system, and comprehensive lifecycle management. Uses MCP protocol and AI agents for end-to-end automation from conversational commands to vulnerability discovery._
      • redamon - _AI-powered agentic red team framework that automates offensive security operations from reconnaissance to exploitation to post-exploitation with zero human intervention._
      • shannon - _Fully autonomous AI pentester for web apps and APIs by Keygraph. White-box security testing that analyzes source code, identifies attack vectors, and executes real exploits. 96.15% success rate (100/104 exploits) on XBOW benchmark._
      • nano-analyzer - _A minimal LLM-powered zero-day vulnerability scanner by AISLE._
      • clearwing - _Autonomous vulnerability scanner and source-code hunter built on LangGraph._
      • Zen-AI-Pentest - _AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting. 72+ security tools, Docker sandbox, ReAct agents, attack path analysis._
      • OpenHack - _AI-powered multi-agent scanner that autonomously finds SQLi, XSS, IDOR, and auth bypass in your codebase, then verifies each finding through sandbox execution and browser replay. On par with Claude Opus 4.6 at roughly 40x lower cost._
      • Violin - _Supervised, agentic Hermes Agent pentest profile: 31 skill-based playbooks (OWASP Top 10, API Top 10, LLM Top 10) with interactive scoping, scope validation, and approval gates for authorised recon, exploit validation, and reporting._
      • NeuroSploit - _Autonomous multi-model pentesting harness in Rust. LLM pool drives recon, agent selection, exploit chaining, and cross-model validation voting across black-box, white-box, grey-box, and cloud engagement modes._
      • PentAGI - _Fully autonomous multi-agent system for complex penetration testing tasks. Sandboxed Docker execution, multi-provider LLM support (OpenAI, Anthropic, Gemini, Ollama, DeepSeek), knowledge graph integration, and real-time agent supervision._
      • V3SP3R - _AI-powered hardware hacking companion for the Flipper Zero. Natural language interface for controlling hardware attacks, with smart glasses integration for hands-free operation._
      • BugTraceAI - _Open-source multi-agent platform for authorized web application security testing with validation, evidence capture, and reporting._
    • LLM & GenAI Red Teaming

      • EasyEdit - _Modify an LLM's ground truths_
      • spikee - _Simple Prompt Injection Kit for Evaluation and Exploitation_
      • Agentic Radar - _Open-source CLI security scanner for agentic workflows._
      • Prompt Hacking Resources - _A list of curated resources for people interested in AI Red Teaming, Jailbreaking, and Prompt Injection_
      • llamator - _Framework for testing vulnerabilities of large language models (LLM)._
      • whistleblower - _Offensive security tool for testing against system prompt leakage and capability discovery of an AI application exposed through API_
      • LLMFuzzer - _LLMFuzzer is the first open-source fuzzing framework specifically designed for Large Language Models (LLMs), especially for their integrations in applications via LLM APIs._
      • vigil-llm - _Detect prompt injections, jailbreaks, and other potentially risky Large Language Model (LLM) inputs_
      • FuzzyAI - _A powerful tool for automated LLM fuzzing. It is designed to help developers and security researchers identify and mitigate potential jailbreaks in their LLM APIs._
      • EasyJailbreak - _An easy-to-use Python framework to generate adversarial jailbreak prompts._
      • promptmap - _a prompt injection scanner for custom LLM applications_
      • PyRIT - _The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to proactively identify risks in generative AI systems._
      • PurpleLlama - _Set of tools to assess and improve LLM security._
      • Giskard - _Open-Source Evaluation & Testing for AI & LLM systems_
      • promptfoo - _Test your prompts, agents, and RAGs. Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration._
      • HouYi - _The automated prompt injection framework for LLM-integrated applications._
      • llm-attacks - _Universal and Transferable Attacks on Aligned Language Models_
      • Plexiglass - _A toolkit for detecting and protecting against vulnerabilities in Large Language Models (LLMs)._
      • ps-fuzz - _Make your GenAI Apps Safe & Secure — Test & harden your system prompt_
      • Dropbox llm-security - _Dropbox LLM Security research code and results_
      • llm-security - _New ways of breaking app-integrated LLMs_
      • gptfuzz - _Official repo for GPTFUZZER: Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts_
      • garak - _security probing tool for LLMs_
      • agentic_security - _Agentic LLM Vulnerability Scanner / AI red teaming kit_
      • blackice - _BlackIce is an open-source containerized toolkit designed for red teaming AI models, including Large Language Models (LLMs) and classical machine learning (ML) models. Inspired by the convenience and standardization of Kali Linux in traditional penetration testing, BlackIce simplifies AI security assessments by providing a reproducible container image preconfigured with specialized evaluation tools._
      • augustus - _LLM security testing framework for detecting prompt injection, jailbreaks, and adversarial attacks. 190+ probes, 28 providers, single Go binary. Production-ready with concurrent scanning, rate limiting, and retry logic._
      • claude-secure-coding-rules - _Open-source security rules that guide Claude Code to generate secure code by default._
      • ai-best-practices - _Semgrep Pro Rules to ensure code using LLMs is following best practices. 58 rules, 102 sub-rules covering 6 providers + MCP + Claude Code & Cursor hooks + LangChain. Detects hardcoded API keys, prompt injection risks, missing safety checks, and unhandled errors across 7 languages._
      • ai-scanner - _Open-source web application for AI model security assessments, built on NVIDIA garak. Features 179 probes, multi-target scanning, scheduled scans, ASR scoring, and SIEM integration._
      • G0DM0D3 - _Open-source multi-model chat interface for red teaming with 50+ models via OpenRouter. Features GODMODE CLASSIC (5 jailbreak combos), ULTRAPLINIAN multi-model evaluation, Parseltongue input perturbation engine with 33 red team techniques, and AutoTune adaptive sampling for AI safety research._
      • RAPTOR - _Autonomous offensive/defensive security research framework built on Claude Code. Chains static analysis (Semgrep, CodeQL), binary analysis, LLM-powered vulnerability validation, exploit generation, and patch writing. Multi-model orchestration with Z3-based feasibility analysis._
      • DeepTeam - _LLM red teaming framework with 40+ attack methods including prompt injection, jailbreaking, and RAG poisoning. Integrates with CI/CD pipelines._
      • L1B3RT4S - _Collection of jailbreak and liberation prompts for major LLMs. Curated library of adversarial prompts designed to test and evaluate AI safety guardrails across ChatGPT, Claude, Gemini, and other frontier models._
      • OBLITERATUS - _Abliteration toolkit that removes refusal behaviors from open-source LLMs without retraining. Modifies model weights to eliminate safety-aligned refusal responses, enabling unrestricted model behavior research._
      • T3MP3ST - _Autonomous red teaming platform and multi-agent offensive-security meta-harness. Coordinates swarms of AI agents for coordinated adversarial testing of frontier AI systems._
      • P4RS3LT0NGV3 - _Universal text transformation and promptcrafting toolkit. Supports translation, mutation, encoding/decoding, and adversarial prompt engineering for jailbreak payload construction._
      • PoisonedRAG - _Knowledge Corruption Attacks to Retrieval-Augmented Generation (USENIX Security 2025)._
    • Steganography & Covert Channels

      • ST3GG - _All-in-one steganography suite with multi-layer encoding, image and audio steganography, and steganalysis tools for detecting hidden data in AI-generated media._
  • Benchmarks & Evaluations

    • AI-Assisted Offensive Security

    • Steganography & Covert Channels

      • AIRTBench - _Code Repository for: AIRTBench: Measuring Autonomous AI Red Teaming Capabilities in Language Models_
      • AgentDojo - _A Dynamic Environment to Evaluate Attacks and Defenses for LLM Agents._
      • jailbreakbench - _JailbreakBench: An Open Robustness Benchmark for Jailbreaking Language Models [NeurIPS 2024 Datasets and Benchmarks Track]_
      • AgentDoG - _AgentDoG is a risk-aware evaluation and guarding framework for autonomous agents. It focuses on trajectory-level risk assessment, aiming to determine whether an agent's execution trajectory contains safety risks under diverse application scenarios._
      • ISC-Bench - _Internal Safety Collapse: jailbreaks any frontier LLM (Claude Opus 4.6, GPT-5.4) in pass@3 via normal task completion — no adversarial prompting. Black-box, cross-domain, cross-science. Novel failure mode._ [[Paper]](https://arxiv.org/abs/2603.23509)
      • AICGSecEval - _Tencent's comprehensive evaluation benchmark for AI code generation security, covering 10 CWE categories with automated test harness_
      • Inspect - _Framework for large language model evaluations by the UK AI Security Institute. 200+ pre-built evaluations covering prompt engineering, tool usage, multi-turn dialog, and model-graded scoring._
      • sec-code-bench - _Alibaba's benchmark for evaluating LLM code security capabilities across 17 vulnerability categories and 4 programming languages_
      • HackingBuddyGPT benchmark dataset - _Benchmark dataset for automated pentesting_
  • Datasets

    • Domain-Adapted Security Language Models

      • SafetyPrompts - _Curated collection of safety-relevant prompts for evaluating LLM safety and security properties._
      • Do-Not-Answer - _Dataset of prompts that responsible LLMs should not answer, for safety evaluation and red teaming._
      • JailBreakV-28K - _Large-scale dataset of 28,000 jailbreak prompts for benchmarking LLM safety._
      • Leaked System Prompts - _Collection of leaked system prompts from commercial AI tools — useful for understanding real-world prompt engineering and attack surfaces._
      • CL4R1T4S - _Leaked system prompts from ChatGPT, Claude, Gemini, Grok, Perplexity, Cursor, Lovable, Replit, and other major AI tools. Largest known collection of production system prompts for transparency and attack-surface research._
      • LEAKHUB - _System Prompt Leak Leaderboard — community platform for tracking and ranking system prompt leaks across AI products._
      • SemGuard Arabic Security Dataset - _First validated Arabic/Arabizi LLM security dataset — 807 examples across 7 threat categories, validated via 3-judge LLM-as-Judge pipeline (GPT-4o, Grok-4, Llama 3.3 70B), Fleiss' κ=0.839. Includes a 527-example inter-judge disagreement corpus._
  • Defense & Security Controls

    • Agent Runtime Security & Sandboxing

      • vibekit - _Run Claude Code, Gemini, Codex — or any coding agent — in a clean, isolated sandbox with sensitive data redaction and observability baked in._
      • claude-code-safety-net - _A Claude Code plugin that acts as a safety net, catching destructive git and filesystem commands before they execute_
      • leash - _Leash wraps AI coding agents in containers and monitors their activity._
      • skill-scanner - _A security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. Combines pattern-based detection (YAML + YARA), LLM-as-a-judge, and behavioral dataflow analysis for comprehensive threat detection._
      • openclaw-shield - _Security plugin for OpenClaw agents - prevents secret leaks, PII exposure, and destructive command execution_
      • Project CodeGuard - _CoSAI Open Source Project for securing AI-assisted development workflows. CodeGuard provides security controls and guardrails for AI coding assistants to prevent vulnerabilities from being introduced during AI-generated code development._
      • pipelock - _Security harness for AI agents — egress proxy with DLP scanning, SSRF protection, MCP response scanning, and workspace integrity monitoring_
      • claude-code-devcontainer - _Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review._
      • clawsec - _Security scanner and hardening tool for OpenClaw deployments. Provides security assessments, configuration auditing, and vulnerability detection specifically for OpenClaw gateway and agent configurations._
      • nanoclaw - _Lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK. First AI assistant to support Agent Swarms for collaborative agent teams._
      • secureclaw - _Automated security hardening for OpenClaw AI agents by Adversa AI. 51 audit checks, 12 behavioral rules, 9 scripts, 4 pattern databases. Full OWASP ASI Top 10 coverage. Protects against prompt injection, credential theft, supply chain attacks, and privacy leaks._
      • agentfield - _Open-source control plane for agent systems with cryptographic identity, policy enforcement, and audit-friendly observability._
      • Aegis - _Open-source EDR for AI agents by Antropos. Monitor processes, files, network, and behavior of autonomous AI agents in real time. No telemetry, no cloud, everything stays local._
      • AgentLens - _Agent observability and replay tooling for AI safety & interpretability research. Harness for running multi-session agent trajectories, capturing them in ATIF format, and tracking file state changes across sessions. Built for studying LLM agent behavior across multi-turn, multi-session, multi-agent interactions._
      • Microsoft Agent Governance Toolkit - _AI Agent Governance Toolkit from Microsoft — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10._
      • OneCLI - _Open-source credential vault for AI agents. Rust HTTP gateway intercepts agent requests and injects API credentials transparently so agents never hold raw keys. AES-256-GCM encryption, per-agent scoping, full audit trail._
      • OpenShell - _OpenShell is the safe, private runtime for autonomous AI agents. It provides sandboxed execution environments governed by declarative YAML policies that prevent unauthorized file access, data exfiltration, and uncontrolled network activity._
      • OpenSandbox - _Secure, Fast, and Extensible Sandbox runtime for AI agents. Multi-language SDKs, Docker/Kubernetes runtimes, gVisor/Kata Containers/Firecracker isolation. CNCF Landscape project._
      • defenseclaw - _Enterprise governance layer for OpenClaw from Cisco AI Defense. Scans skills, MCP servers, and plugins with built-in CodeGuard SAST, tool call inspection engine, LLM guardrail proxy, and SIEM integration. Auto-blocks HIGH/CRITICAL findings._
      • CubeSandbox - _Instant, concurrent, secure & lightweight sandbox for AI agents by Tencent Cloud. Sub-60ms cold start, <5MB memory overhead, E2B SDK compatible. Built on RustVMM and KVM with extreme isolation (dedicated kernel + eBPF)._
      • SkillSpector - _Security scanner for AI agent skills. Detects 64 vulnerability patterns across 16 categories with static analysis + optional LLM semantic evaluation. Multi-format output (JSON, Markdown, SARIF)._
      • microsandbox - _Lightweight microVM sandbox for running untrusted AI-generated code safely with strong isolation guarantees_
      • Adrian - _Open-source, AARM-aligned runtime security monitoring and control engine for AI agents by Secure Agentics. Analyses agent activity logs (tool calls, actions, outputs) and reasoning traces to detect malicious, misaligned, or out-of-remit behaviour, with optional in-flight intervention (audit vs block mode). Python (LangChain/LangGraph) and TypeScript SDKs, fully self-hostable offline. Apache-2.0._
      • HOL Guard - _Local-first security harness that intercepts tool calls in AI coding agents (Codex, Claude Code, Cursor, Gemini, Copilot, Hermes, OpenCode) before files change or network is contacted. Pre-tool hooks, approval center, supply-chain advisory scanning, and optional Guard Cloud sync._
      • ADR - _Enterprise agentic AI detection and response — observability, security benchmarking (300+ tasks, 133 MCP servers), and dual-agent threat detection. Deployed at Uber. MLSys 2026._
      • OWASP Agent Memory Guard - _Runtime defense layer for AI agent memory. Screens every memory read/write through detectors (prompt injection, secret/PII leakage, protected-key tampering, anomalies) and a YAML policy (allow/redact/quarantine/block), with SHA-256 integrity baselines, snapshots/rollback, and structured security events. Reference implementation for OWASP ASI06 Memory & Context Poisoning. Apache-2.0._
      • Agent Safehouse - _macOS sandbox for LLM coding agents using sandbox-exec with composable policy profiles and a deny-first model._
      • Bernstein - _Open-source governance layer for AI agents, covering CLI coding agents (Claude Code, Codex, Gemini CLI, Aider, and 40+ more) as well as self-hosted and hosted model endpoints. Runs each task in an isolated git worktree with per-agent credential scoping, PII gating, and a policy engine. No model sits in the coordination loop, so runs replay byte-identically, and an opt-in HMAC-chained audit log with signed per-artifact lineage can be verified offline with `bernstein audit verify`. Apache-2.0._
      • Doberman - _Runtime authorization layer between a coding agent and its tools. A local policy engine gives every tool call an allow/authenticate/block verdict before it executes; blocks carry reason codes, logs redact secrets to HMAC fingerprints, and errors fail closed. Ships an MCP proxy plus Claude Code and Codex adapters. Apache-2.0._
    • AI-Assisted Defensive Security

      • Claude Code Security Review - _An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities._
      • GhidraGPT - _Integrates GPT models into Ghidra for automated code analysis, variable renaming, vulnerability detection, and explanation generation._
      • claude-grc-plugin - _Claude Code plugin that turns Claude into a senior GRC analyst. 72+ reference files covering 15 frameworks (NIST 800-53, FedRAMP, ISO 27001, SOC 2, etc.), 24 slash commands, and deep domain knowledge for federal and commercial compliance work._
      • IDAssist - _AI-Powered Reverse Engineering Plugin for IDA Pro. Integrates LLM-powered analysis into IDA's interface with semantic knowledge graphs, RAG document search, and support for multiple LLM providers (OpenAI, Anthropic, Ollama, LiteLLM). Analyzes functions, suggests renames, answers questions about code._
      • ThreatForest - _Agentic threat modeling platform built on Strands framework. Autonomously generates attack trees from repositories, maps attack steps to MITRE ATT&CK techniques, and produces actionable mitigation recommendations._
      • Vigil SOC - _A comprehensive open-source security operations platform for AI agents, enabling real-time monitoring, threat detection, and incident response for AI-powered environments._
      • deepsec - _Agent-powered vulnerability scanner by Vercel Labs for finding hard-to-spot issues in large codebases using coding agents. Supports parallel scanning, PR diff review, and CI/CD integration._
      • defending-code-reference-harness - _Reference implementation for autonomous vulnerability discovery and remediation using Claude. Includes threat modeling, scanning, triage, and patching skills._
      • AiSOC - _Open-source, self-hostable AI-powered SOC that ingests security events, correlates them, runs autonomous AI-driven investigations via LangGraph, and surfaces results in a unified console. Features full agent decision audit trail, public eval harness in CI, and 52 first-party connectors. MIT licensed._
      • Visa Vulnerability Agentic Harness - _Agentic SAST pipeline with 11 stages from detection through LLM-powered remediation and adversarial validation. Outputs SARIF, integrates with Claude Code, Copilot, and Gemini._
      • OpenCodeReview - _AI-powered code review CLI from Alibaba with deterministic pipelines + LLM agent, line-level precision, and built-in security rulesets (NPE, thread-safety, XSS, SQL injection)._
    • Data & Supply Chain Security

      • datasig - _Dataset fingerprinting for AIBOM_
      • OWASP AIBOM - _AI Bill of Materials_
      • Trusera ai-bom - _AI Bill of Materials — discover every AI agent, model, and API in your infrastructure_
    • Input/Output Guardrails

      • langkit - _LangKit is an open-source text metrics toolkit for monitoring language models. The toolkit provides various security related metrics that can be used to detect attacks_
      • LlamaFirewall - _LlamaFirewall is a framework designed to detect and mitigate AI centric security risks, supporting multiple layers of inputs and outputs, such as typical LLM chat and more advanced multi-step agentic operations._
      • ZenGuard AI - _The fastest Trust Layer for AI Agents_
      • llm-guard - _LLM Guard by Protect AI is a comprehensive tool designed to fortify the security of Large Language Models (LLMs)._
      • vibraniumdome - _Full blown, end to end LLM WAF for Agents, allowing security teams governance, auditing, policy driven control over Agents usage of language models._
      • NeMo-Guardrails - _NeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems._
      • DynaGuard - _A Dynamic Guardrail Model With User-Defined Policies_
      • TrustGate - _Generative Application Firewall (GAF) to detect, prevent and block attacks against GenAI Applications_
      • AprielGuard - _8B parameter safety–security safeguard model_
      • superagent - _Superagent provides purpose-trained guardrails that make AI-agents secure and compliant._
      • LocalMod - _Self-hosted content moderation API with prompt injection detection, toxicity filtering, PII detection, and NSFW classification. Runs 100% offline._
      • Safe Zone - _Safe Zone is an open-source PII detection and guardrails engine that prevents sensitive data from leaking to LLMs and third-party APIs._
      • rebuff - _Prompt Injection Detector_
      • ShellWard - _AI Agent Security Middleware with 8-layer defense against prompt injection, data exfiltration & dangerous commands. Zero dependencies._
      • Future AGI - _Open-source self-hostable platform with built-in real-time guardrails for unsafe outputs (jailbreak, PII, injection, toxicity), evals, tracing, simulations, and gateway for LLM and agent applications._
      • Prompt Injection Defenses - _Comprehensive collection of every practical and proposed defense against prompt injection._
      • CodeGate - _An open-source, privacy-focused project that acts as a layer of security within a developer's Code Generation AI workflow_
    • MCP Security

      • MCP-Scan - _A security scanning tool for MCP servers_
      • MCP-Security-Checklist - _A comprehensive security checklist for MCP-based AI tools. Built by SlowMist to safeguard LLM plugin ecosystems._
      • Awesome-MCP-Security - _Everything you need to know about Model Context Protocol (MCP) security._
      • secure-mcp-gateway - _This Secure MCP Gateway is built with authentication, automatic tool discovery, caching, and guardrail enforcement._
      • mcp-context-protector - _context-protector is a security wrapper for MCP servers that addresses risks associated with running untrusted MCP servers, including line jumping, unexpected server configuration changes, and other prompt injection attacks_
      • MCP Audit VSCode Extension - _Audit and log all GitHub Copilot MCP tool calls in VSCode centrally with ease._
      • ATR (Agent Threat Rules) - _Open-source detection rules for AI agent threats. 108 regex rules covering prompt injection, tool poisoning, credential exfiltration across 9 categories. Used by Cisco AI Defense. MIT licensed._
      • MCPProxy - _Local-first MCP proxy with per-tool SHA-256 quarantine to detect tool-poisoning and rug-pull attacks, automatic sensitive-data and secret scanning of tool calls, Docker sandbox isolation for untrusted MCP servers, and OAuth 2.1. MIT licensed._
      • mcp-guardian - _MCP Guardian manages your LLM assistant's access to MCP servers, handing you realtime control of your LLM's activity._
    • Model & Artifact Scanning

      • modelscan - _ModelScan is an open source project from Protect AI that scans models to determine if they contain unsafe code._
      • picklescan - _Security scanner detecting Python Pickle files performing suspicious actions_
      • fickling - _A Python pickling decompiler and static analyzer_
      • a2a-scanner - _Scan A2A agents for potential threats and security issues_
      • medusa - _AI-first security scanner with 74+ analyzers, 180+ AI agent security rules, intelligent false positive reduction. Supports all languages. CVE detection for React2Shell, mcp-remote RCE._
      • julius - _LLM service fingerprinting tool for security professionals. Detects 32+ AI services (Ollama, vLLM, LiteLLM, Hugging Face TGI, etc.) during penetration tests and attack surface discovery. Uses HTTP-based service fingerprinting to identify server infrastructure._
    • Privacy & Confidential Computing

      • PLOT4ai - _Privacy Library Of Threats 4 Artificial Intelligence — A threat modeling library to help you build responsible AI_
      • Cloaked AI - _Open source property-preserving encryption for vector embeddings_
      • PrivacyRaven - _privacy testing library for deep learning systems_
      • Python Differential Privacy Library
      • Diffprivlib - _The IBM Differential Privacy Library_
      • TenSEAL - _A library for doing homomorphic encryption operations on tensors_
      • SyMPC - _A Secure Multiparty Computation companion library for Syft_
      • PyVertical - _Privacy Preserving Vertical Federated Learning_
      • dstack - _Open-source confidential AI framework for secure ML/LLM deployment with hardware-enforced isolation and data privacy_
      • OpenDP - _Core library for differential privacy algorithms from the OpenDP project — used to build privacy-preserving ML training pipelines_
  • Defensive tools and frameworks

    • Detection

      • rebuff - _Prompt Injection Detector_
      • StringSifter - _A machine learning tool that ranks strings based on their relevance for malware analysis_