Security
Authentication, cryptography, vulnerability tooling, and security research projects.
49 tracked repositories, ranked by stars.
49 of 49 repositories
sherlock-project/sherlock
Hunt down social media accounts by username across social networks
AI summary: Command-line tool that hunts down social media accounts by username across over 400 social networks.
88,400securityPythonMITZ4nzu/hackingtool
ALL IN ONE Hacking Tool For Hackers
AI summary: An AI-guided, all-in-one toolkit consolidating over 200 cybersecurity tools for authorized penetration testing.
78,824securityPythonMITasgeirtj/system_prompts_leaks
Extracted system prompts from Anthropic - Claude Fable 5, Opus 5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-5.6-Sol, Codex. Google - Gemini 3.5 Flash, 3.1 Pro, Antigravity. xAI - Grok, Cursor, Copilot, VS Code, Perplexity, and more. Updated regularly.
AI summary: An analytical archive of leaked system prompts from major commercial AI applications.
62,485securityJavaScriptCC0-1.0bannedbook/fanqiang
翻墙-科学上网
AI summary: A comprehensive resource collection for internet censorship circumvention tools and techniques.
49,567securityKotlinusestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
AI summary: Open-source AI penetration testing tool that autonomously finds and fixes vulnerabilities.
49,439securityPythonApache-2.0soxoj/maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
AI summary: An OSINT tool that collects a dossier on a person by username across 3000+ sites.
36,199securityPythonMITimthenachoman/How-To-Secure-A-Linux-Server
An evolving how-to guide for securing a Linux server.
AI summary: An evolving, comprehensive guide and resource for securing and hardening Linux servers.
30,240securityCC-BY-SA-4.0mukul975/Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
AI summary: A curated collection of cybersecurity prompts and workflows for Anthropic's Claude.
27,432securityPythonApache-2.0m1k1o/neko
A self hosted virtual browser that runs in docker and uses WebRTC.
AI summary: A self-hosted virtual browser running in Docker with WebRTC streaming.
21,881securityGoApache-2.0vxcontrol/pentagi
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
AI summary: A fully autonomous AI agent system designed for complex penetration testing.
21,660securityGoMITzhaoxuya520/reverse-skill
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
AI summary: A comprehensive cybersecurity skill routing package that provides structured playbooks and toolchains for AI coding agents.
20,389securityPowerShellMITsimplex-chat/simplex-chat
SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!
AI summary: A hyper-secure messaging platform operating without user identifiers of any kind to guarantee absolute privacy.
19,199securityHaskellAGPL-3.0HunxByts/GhostTrack
Useful tool to track location or mobile number
AI summary: A lightweight, stealthy OSINT tool for tracking digital footprints across public databases and social platforms.
14,758securityPythonamnezia-vpn/amnezia-client
Amnezia VPN Client (Desktop+Mobile)
AI summary: A versatile, open-source VPN client designed specifically for self-hosted server deployments.
14,351securityC++GPL-3.0NVIDIA/SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
AI summary: A security scanner that detects vulnerabilities and malicious patterns in AI agent skills before execution.
14,305securityPythonApache-2.0QuipNetwork/hashsigs-rs
Hash-based post quantum signatures in Rust
AI summary: Core Rust workspace for post-quantum hash-based signature primitives.
11,221securityRustAGPL-3.0QuipNetwork/hashsigs-solidity
Solidity contracts implementing hash based post quantum signatures
AI summary: Solidity implementations of post-quantum hash-based signature verifiers.
11,221securitySolidityAGPL-3.0QuipNetwork/hashsigs-ts
Hash-based signatures in typescript, WOTS+
AI summary: TypeScript library for hash-based post-quantum signatures.
11,204securityTypeScriptAGPL-3.0QuipNetwork/hashsigs-py
AI summary: Python bindings for post-quantum hash-based signatures.
11,195securityPythonAGPL-3.0NoeFabris/opencode-antigravity-auth
Enable Opencode to authenticate against Antigravity (Google's IDE) via OAuth so you can use Antigravity rate limits and access models like gemini-3-pro and claude-opus-4-5-thinking with your Google credentials.
AI summary: A plug-and-play authentication microservice with built-in advanced security features.
11,027securityTypeScriptMITTencentCloud/CubeSandbox
Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.
AI summary: A lightweight, secure sandbox environment for executing untrusted code.
10,958securityRustOtherunicity-sphere/sphere
A Web3 wallet and agent platform for the Unicity network - crypto wallet, DMs, group chat, and marketplace.
AI summary: A universal wallet SDK providing secure token and identity management.
9,765securityTypeScriptsimplifaisoul/osiris
Open Source Global Intelligence Platform - Real-Time OSINT Dashboard - A Palantir Alternative - 2nZNHm3Lr9umG3DVrzYwHgktwkuKuJRXqqRqs3ewpump
AI summary: A GPU-accelerated global OSINT dashboard integrating live flight tracking, CCTV, conflict zones, and crypto tracing.
7,467securityTypeScriptMITanthropics/defending-code-reference-harness
Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
AI summary: A reference implementation for evaluating and defending against vulnerabilities in AI-generated code.
6,960securityPythonOthermasterking32/MasterDnsVPN
Advanced DNS tunneling VPN for censorship bypass, optimized beyond DNSTT and SlipStream with low-overhead ARQ, resolver load balancing, high packet-loss stability and speed.
AI summary: A resilient DNS tunneling VPN designed to bypass total internet blackouts by disguising traffic as normal DNS queries.
6,912securityGoMITvercel-labs/deepsec
Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents
AI summary: An agent-powered vulnerability scanner designed for deep, on-demand review of large-scale codebases.
6,576securityTypeScriptApache-2.0ifixai-ai/iFixAi
Independent Auditing of AI Agents. Run by human or the agent itself, to answer the most crucial question in the AI Agent Economy. Is the agent doing what is supposed to do? With iFixAi you can have this answer in less than 120 seconds.
AI summary: A fast, independent auditing CLI to evaluate AI agent safety, alignment, and hallucinations.
6,558securityPythonApache-2.0trailofbits/skills
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
AI summary: A marketplace of Claude Code skills tailored specifically for security research and vulnerability detection.
6,461securityPythonCC-BY-SA-4.0microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
AI summary: A toolkit for enforcing policy, security, and sandboxing in autonomous AI agents.
5,725securityPythonMITInterceptSuite/ProxyBridge
Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy
AI summary: A network tool that seamlessly bridges non-proxy-aware applications into interception proxies like Burp Suite or ZAP.
5,661securityCMITelder-plinius/T3MP3ST
autonomous red teaming platform; multi-agent offensive-security meta-harness
AI summary: A multi-agent offensive-security framework that turns AI coding assistants into zero-day hunters.
5,459securityTypeScriptAGPL-3.0V4bel/dirtyfrag
AI summary: A highly reliable, universal Linux Local Privilege Escalation exploit chaining two kernel vulnerabilities.
4,967securityCperplexityai/bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
AI summary: A read-only scanner for checking developer endpoints against known supply-chain compromises.
4,884securityGoApache-2.0MDX-Tom/gpt-5.6-instruct
A Codex jailbreak prompt and test pack for gpt-5.6-sol. 针对 gpt-5.6 系列的 Codex 破甲提示词与测试包。
AI summary: A comprehensive jailbreak prompt and testing suite specifically targeting the gpt-5.6-sol model.
4,816securityPythonMITwpzzz/blocked-sites-in-south-korea
AI summary: A community-driven index and checker for websites blocked in South Korea.
4,526securityPythondenuitt1/mhr-cfw
A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.
AI summary: A domain-fronting HTTP relay bypassing DPI via Google Apps Script and Cloudflare Workers.
4,422securityPythonMITbikini/exploitarium
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
AI summary: A curated collection of reproducible exploits, vulnerabilities, and security research tools.
4,179securityPythontheori-io/copy-fail-CVE-2026-31431
Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
AI summary: Technical analysis and exploit code for CVE-2026-31431, a critical 9-year-old Linux kernel privilege escalation vulnerability.
4,030securityPythonbethington/ghidra-mcp
Ghidra MCP Server — 200+ MCP tools for AI-powered reverse engineering. GUI plugin + headless server, lazy tool loading, convention enforcement, batch operations, Ghidra Server integration, and Docker deployment.
AI summary: A production-ready MCP server bridging Ghidra's reverse engineering tools with AI agents.
3,194securityPythonApache-2.0motiful/cc-gateway
AI API identity gateway — reverse proxy that normalizes device fingerprints and telemetry for privacy-preserving API proxying
AI summary: A local proxy gateway designed to give users control over their AI API telemetry and data.
2,994securityTypeScriptMIT