Security

Authentication, cryptography, vulnerability tooling, and security research projects.

49 tracked repositories, ranked by stars.

Filter by topic

49 of 49 repositories

  • sherlock-project/sherlock

    Hunt down social media accounts by username across social networks

    AI summary: Command-line tool that hunts down social media accounts by username across over 400 social networks.

    88,400securityPythonMIT
  • Z4nzu/hackingtool

    ALL IN ONE Hacking Tool For Hackers

    AI summary: An AI-guided, all-in-one toolkit consolidating over 200 cybersecurity tools for authorized penetration testing.

    78,824securityPythonMIT
  • asgeirtj/system_prompts_leaks

    Extracted system prompts from Anthropic - Claude Fable 5, Opus 5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-5.6-Sol, Codex. Google - Gemini 3.5 Flash, 3.1 Pro, Antigravity. xAI - Grok, Cursor, Copilot, VS Code, Perplexity, and more. Updated regularly.

    AI summary: An analytical archive of leaked system prompts from major commercial AI applications.

    62,485securityJavaScriptCC0-1.0
  • bannedbook/fanqiang

    翻墙-科学上网

    AI summary: A comprehensive resource collection for internet censorship circumvention tools and techniques.

    49,567securityKotlin
  • usestrix/strix

    Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

    AI summary: Open-source AI penetration testing tool that autonomously finds and fixes vulnerabilities.

    49,439securityPythonApache-2.0
  • soxoj/maigret

    🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

    AI summary: An OSINT tool that collects a dossier on a person by username across 3000+ sites.

    36,199securityPythonMIT
  • imthenachoman/How-To-Secure-A-Linux-Server

    An evolving how-to guide for securing a Linux server.

    AI summary: An evolving, comprehensive guide and resource for securing and hardening Linux servers.

    30,240securityCC-BY-SA-4.0
  • mukul975/Anthropic-Cybersecurity-Skills

    817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

    AI summary: A curated collection of cybersecurity prompts and workflows for Anthropic's Claude.

    27,432securityPythonApache-2.0
  • m1k1o/neko

    A self hosted virtual browser that runs in docker and uses WebRTC.

    AI summary: A self-hosted virtual browser running in Docker with WebRTC streaming.

    21,881securityGoApache-2.0
  • vxcontrol/pentagi

    Fully autonomous AI Agents system capable of performing complex penetration testing tasks

    AI summary: A fully autonomous AI agent system designed for complex penetration testing.

    21,660securityGoMIT
  • zhaoxuya520/reverse-skill

    Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

    AI summary: A comprehensive cybersecurity skill routing package that provides structured playbooks and toolchains for AI coding agents.

    20,389securityPowerShellMIT
  • simplex-chat/simplex-chat

    SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!

    AI summary: A hyper-secure messaging platform operating without user identifiers of any kind to guarantee absolute privacy.

    19,199securityHaskellAGPL-3.0
  • HunxByts/GhostTrack

    Useful tool to track location or mobile number

    AI summary: A lightweight, stealthy OSINT tool for tracking digital footprints across public databases and social platforms.

    14,758securityPython
  • amnezia-vpn/amnezia-client

    Amnezia VPN Client (Desktop+Mobile)

    AI summary: A versatile, open-source VPN client designed specifically for self-hosted server deployments.

    14,351securityC++GPL-3.0
  • NVIDIA/SkillSpector

    Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.

    AI summary: A security scanner that detects vulnerabilities and malicious patterns in AI agent skills before execution.

    14,305securityPythonApache-2.0
  • QuipNetwork/hashsigs-rs

    Hash-based post quantum signatures in Rust

    AI summary: Core Rust workspace for post-quantum hash-based signature primitives.

    11,221securityRustAGPL-3.0
  • QuipNetwork/hashsigs-solidity

    Solidity contracts implementing hash based post quantum signatures

    AI summary: Solidity implementations of post-quantum hash-based signature verifiers.

    11,221securitySolidityAGPL-3.0
  • QuipNetwork/hashsigs-ts

    Hash-based signatures in typescript, WOTS+

    AI summary: TypeScript library for hash-based post-quantum signatures.

    11,204securityTypeScriptAGPL-3.0
  • QuipNetwork/hashsigs-py

    AI summary: Python bindings for post-quantum hash-based signatures.

    11,195securityPythonAGPL-3.0
  • NoeFabris/opencode-antigravity-auth

    Enable Opencode to authenticate against Antigravity (Google's IDE) via OAuth so you can use Antigravity rate limits and access models like gemini-3-pro and claude-opus-4-5-thinking with your Google credentials.

    AI summary: A plug-and-play authentication microservice with built-in advanced security features.

    11,027securityTypeScriptMIT
  • TencentCloud/CubeSandbox

    Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.

    AI summary: A lightweight, secure sandbox environment for executing untrusted code.

    10,958securityRustOther
  • unicity-sphere/sphere

    A Web3 wallet and agent platform for the Unicity network - crypto wallet, DMs, group chat, and marketplace.

    AI summary: A universal wallet SDK providing secure token and identity management.

    9,765securityTypeScript
  • simplifaisoul/osiris

    Open Source Global Intelligence Platform - Real-Time OSINT Dashboard - A Palantir Alternative - 2nZNHm3Lr9umG3DVrzYwHgktwkuKuJRXqqRqs3ewpump

    AI summary: A GPU-accelerated global OSINT dashboard integrating live flight tracking, CCTV, conflict zones, and crypto tracing.

    7,467securityTypeScriptMIT
  • anthropics/defending-code-reference-harness

    Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

    AI summary: A reference implementation for evaluating and defending against vulnerabilities in AI-generated code.

    6,960securityPythonOther
  • masterking32/MasterDnsVPN

    Advanced DNS tunneling VPN for censorship bypass, optimized beyond DNSTT and SlipStream with low-overhead ARQ, resolver load balancing, high packet-loss stability and speed.

    AI summary: A resilient DNS tunneling VPN designed to bypass total internet blackouts by disguising traffic as normal DNS queries.

    6,912securityGoMIT
  • vercel-labs/deepsec

    Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents

    AI summary: An agent-powered vulnerability scanner designed for deep, on-demand review of large-scale codebases.

    6,576securityTypeScriptApache-2.0
  • ifixai-ai/iFixAi

    Independent Auditing of AI Agents. Run by human or the agent itself, to answer the most crucial question in the AI Agent Economy. Is the agent doing what is supposed to do? With iFixAi you can have this answer in less than 120 seconds.

    AI summary: A fast, independent auditing CLI to evaluate AI agent safety, alignment, and hallucinations.

    6,558securityPythonApache-2.0
  • trailofbits/skills

    Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

    AI summary: A marketplace of Claude Code skills tailored specifically for security research and vulnerability detection.

    6,461securityPythonCC-BY-SA-4.0
  • microsoft/agent-governance-toolkit

    AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

    AI summary: A toolkit for enforcing policy, security, and sandboxing in autonomous AI agents.

    5,725securityPythonMIT
  • InterceptSuite/ProxyBridge

    Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy

    AI summary: A network tool that seamlessly bridges non-proxy-aware applications into interception proxies like Burp Suite or ZAP.

    5,661securityCMIT
  • elder-plinius/T3MP3ST

    autonomous red teaming platform; multi-agent offensive-security meta-harness

    AI summary: A multi-agent offensive-security framework that turns AI coding assistants into zero-day hunters.

    5,459securityTypeScriptAGPL-3.0
  • V4bel/dirtyfrag

    AI summary: A highly reliable, universal Linux Local Privilege Escalation exploit chaining two kernel vulnerabilities.

    4,967securityC
  • perplexityai/bumblebee

    Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.

    AI summary: A read-only scanner for checking developer endpoints against known supply-chain compromises.

    4,884securityGoApache-2.0
  • MDX-Tom/gpt-5.6-instruct

    A Codex jailbreak prompt and test pack for gpt-5.6-sol. 针对 gpt-5.6 系列的 Codex 破甲提示词与测试包。

    AI summary: A comprehensive jailbreak prompt and testing suite specifically targeting the gpt-5.6-sol model.

    4,816securityPythonMIT
  • wpzzz/blocked-sites-in-south-korea

    AI summary: A community-driven index and checker for websites blocked in South Korea.

    4,526securityPython
  • denuitt1/mhr-cfw

    A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

    AI summary: A domain-fronting HTTP relay bypassing DPI via Google Apps Script and Cloudflare Workers.

    4,422securityPythonMIT
  • bikini/exploitarium

    A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.

    AI summary: A curated collection of reproducible exploits, vulnerabilities, and security research tools.

    4,179securityPython
  • theori-io/copy-fail-CVE-2026-31431

    Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

    AI summary: Technical analysis and exploit code for CVE-2026-31431, a critical 9-year-old Linux kernel privilege escalation vulnerability.

    4,030securityPython
  • bethington/ghidra-mcp

    Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.

    AI summary: A production-ready MCP server bridging Ghidra's reverse engineering tools with AI agents.

    3,194securityPythonApache-2.0
  • motiful/cc-gateway

    AI API identity gateway — reverse proxy that normalizes device fingerprints and telemetry for privacy-preserving API proxying

    AI summary: A local proxy gateway designed to give users control over their AI API telemetry and data.

    2,994securityTypeScriptMIT