Trending repositories: security
48 tracked repositories tagged with security, ordered by stars. Use the topic filters below to narrow further.
48 of 48 repositories
trimstray/the-book-of-secret-knowledge
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
AI summary: A comprehensive collection of manuals, cheatsheets, and tools for IT professionals and researchers.
237,156developer-toolsMITx1xhlol/system-prompts-and-models-of-ai-tools
FULL Augment Code, Claude Code, Cluely, CodeBuddy, Comet, Cursor, Devin AI, Junie, Kiro, Leap.new, Lovable, Manus, NotionAI, Orchids.app, Perplexity, Poke, Qoder, Replit, Same.dev, Trae, Traycer AI, VSCode Agent, Warp.dev, Windsurf, Xcode, Z.ai Code, Dia & v0. (And other Open Sourced) System Prompts, Internal Tools & AI Models
AI summary: A collection of leaked or reverse-engineered system prompts and model details from popular AI tools.
142,640ai-mlGPL-3.0Developer-Y/cs-video-courses
List of Computer Science courses with video lectures.
AI summary: A heavily curated index of free, university-level computer science video lectures covering every major discipline.
82,947learningdaytonaio/daytona
Daytona is a Secure and Elastic Infrastructure for Running AI-Generated Code
AI summary: Secure and elastic infrastructure runtime designed for executing AI-generated code and agent workflows.
72,024infrastructureasgeirtj/system_prompts_leaks
Extracted system prompts from Anthropic - Claude Fable 5, Opus 5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-5.6-Sol, Codex. Google - Gemini 3.5 Flash, 3.1 Pro, Antigravity. xAI - Grok, Cursor, Copilot, VS Code, Perplexity, and more. Updated regularly.
AI summary: An analytical archive of leaked system prompts from major commercial AI applications.
62,485securityJavaScriptCC0-1.0usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
AI summary: Open-source AI penetration testing tool that autonomously finds and fixes vulnerabilities.
49,439securityPythonApache-2.0KeygraphHQ/shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
AI summary: A high-performance, open-source knowledge graph engine optimized for fast querying and AI integration.
46,488dataTypeScriptAGPL-3.0nanocoai/nanoclaw
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
AI summary: A lightweight, secure alternative to OpenClaw that runs AI agents in isolated Linux containers.
30,464ai-mlTypeScriptMITnanocoai/nanoclaw
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
AI summary: A lightweight AI assistant framework that securely runs agents in isolated Linux containers.
30,392productivityTypeScriptMITnanocoai/nanoclaw
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
AI summary: A lightweight AI assistant framework that securely runs agents in isolated Linux containers.
30,391productivityTypeScriptMITimthenachoman/How-To-Secure-A-Linux-Server
An evolving how-to guide for securing a Linux server.
AI summary: An evolving, comprehensive guide and resource for securing and hardening Linux servers.
30,240securityCC-BY-SA-4.0mukul975/Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
AI summary: A curated collection of cybersecurity prompts and workflows for Anthropic's Claude.
27,432securityPythonApache-2.0alibaba/open-code-review
Fast, efficient, battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in multi-language ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
AI summary: A hybrid architecture code review tool tested at Alibaba's scale.
19,438developer-toolsGoApache-2.0simplex-chat/simplex-chat
SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!
AI summary: A hyper-secure messaging platform operating without user identifiers of any kind to guarantee absolute privacy.
19,199securityHaskellAGPL-3.0google/magika
Fast and accurate AI powered file content types detection
AI summary: A highly optimized, AI-powered file type detection tool achieving 99% accuracy within milliseconds.
17,918ai-mlPythonApache-2.0HunxByts/GhostTrack
Useful tool to track location or mobile number
AI summary: A lightweight, stealthy OSINT tool for tracking digital footprints across public databases and social platforms.
14,758securityPythonnearai/ironclaw
IronClaw is an Agent OS focused on privacy, security and extensibility
AI summary: A secure, privacy-focused Agent OS built in Rust and WebAssembly.
12,597systemsRustApache-2.0opensandbox-group/OpenSandbox
Secure, Fast, and Extensible Sandbox runtime for AI agents.
AI summary: A secure, Kubernetes-native runtime environment specifically for executing AI agents.
12,366infrastructurePythonApache-2.0opensandbox-group/OpenSandbox
Secure, Fast, and Extensible Sandbox runtime for AI agents.
AI summary: A secure, high-performance, and extensible sandbox runtime environment designed specifically for AI agents.
12,221infrastructurePythonApache-2.0QuipNetwork/hashsigs-py
AI summary: Python bindings for post-quantum hash-based signatures.
11,195securityPythonAGPL-3.0NoeFabris/opencode-antigravity-auth
Enable Opencode to authenticate against Antigravity (Google's IDE) via OAuth so you can use Antigravity rate limits and access models like gemini-3-pro and claude-opus-4-5-thinking with your Google credentials.
AI summary: A plug-and-play authentication microservice with built-in advanced security features.
11,027securityTypeScriptMITTencentCloud/CubeSandbox
Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.
AI summary: A lightweight, secure sandbox environment for executing untrusted code.
10,958securityRustOtherastrid-runtime/astrid
Astrid is a portable, capability-secure operating system for composable software.
AI summary: A highly isolated, WebAssembly-based agent runtime designed for multi-tenant, zero-trust AI workloads.
10,306systemsRustApache-2.0astrid-runtime/astrid
Astrid is a portable, capability-secure operating system for composable software.
AI summary: A highly isolated, WebAssembly-based agent runtime designed for multi-tenant, zero-trust AI workloads.
10,303systemsRustApache-2.0pydantic/monty
A minimal, secure Python interpreter written in Rust for use by AI
AI summary: A minimal, secure Python interpreter written in Rust specifically for use by AI agents.
7,988developer-toolsRustMITanthropics/defending-code-reference-harness
Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
AI summary: A reference implementation for evaluating and defending against vulnerabilities in AI-generated code.
6,960securityPythonOthermasterking32/MasterDnsVPN
Advanced DNS tunneling VPN for censorship bypass, optimized beyond DNSTT and SlipStream with low-overhead ARQ, resolver load balancing, high packet-loss stability and speed.
AI summary: A resilient DNS tunneling VPN designed to bypass total internet blackouts by disguising traffic as normal DNS queries.
6,912securityGoMITvercel-labs/deepsec
Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents
AI summary: An agent-powered vulnerability scanner designed for deep, on-demand review of large-scale codebases.
6,576securityTypeScriptApache-2.0trailofbits/skills
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
AI summary: A marketplace of Claude Code skills tailored specifically for security research and vulnerability detection.
6,461securityPythonCC-BY-SA-4.0microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
AI summary: A toolkit for enforcing policy, security, and sandboxing in autonomous AI agents.
5,725securityPythonMITInterceptSuite/ProxyBridge
Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy
AI summary: A network tool that seamlessly bridges non-proxy-aware applications into interception proxies like Burp Suite or ZAP.
5,661securityCMITDicklesworthstone/destructive_command_guard
The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.
AI summary: A high-performance safety hook that blocks AI agents from executing destructive commands.
5,653developer-toolsRustOthermitchellh/vouch
A community trust management system based on explicit vouches to participate.
AI summary: A minimal, generic community trust management system based on explicit vouches.
5,043developer-toolsNushellMITperplexityai/bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
AI summary: A read-only scanner for checking developer endpoints against known supply-chain compromises.
4,884securityGoApache-2.0denuitt1/mhr-cfw
A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.
AI summary: A domain-fronting HTTP relay bypassing DPI via Google Apps Script and Cloudflare Workers.
4,422securityPythonMITbikini/exploitarium
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
AI summary: A curated collection of reproducible exploits, vulnerabilities, and security research tools.
4,179securityPythonsanyuan0704/sanyuan-skills
Expert code review skill: SOLID, security, performance, error handling, boundary conditions
AI summary: An expert code review skill for Claude Code focusing on SOLID principles, security, and performance.
3,790developer-toolsPythonMITtamnd/kage
Shadow any website for offline viewing, with the JavaScript stripped out
AI summary: Clones websites for offline viewing by snapshotting the DOM and stripping all JavaScript.
3,127developer-toolsGoMITmotiful/cc-gateway
AI API identity gateway — reverse proxy that normalizes device fingerprints and telemetry for privacy-preserving API proxying
AI summary: A local proxy gateway designed to give users control over their AI API telemetry and data.
2,994securityTypeScriptMITmoltis-org/moltis
A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord, Teams, and MCP tools. Secure by design, runs on your hardware.
AI summary: A secure, sandboxed personal agent server written in Rust, compiled into a single binary.
2,812systemsRustMIT