Top Security Projects

Top security tools gaining traction on GitHub. Vulnerability scanners, pentesting tools, and security frameworks.

nearai/ ironclaw
100%

Run powerful personal AI locally with unbreakable privacy and zero leaks.

Rust 3969 424 27d
sanyuan0704/ code-review-expert
100%

ai grills git changes like a senior engineer.

2434 197 26d
sheeki03/ tirith
100%

Your terminal spots browser-level tricks before they execute anything shady.

Rust 1936 68 28d
lukehinds/ nono
100%

kernels leash rogue ai agents permanently.

Rust 679 53 30d
prompt-security/ clawsec
100%

Your AI agents detect and deflect threats on full autopilot.

JavaScript 550 56 25d
pocketpaw/ pocketpaw
100%

Someone built a self-hosted AI agent that automates your daily chores effortlessly.

Python 528 177 28d
AgentShepherd/ agentshepherd
100%

keeps ai agents from sniffing your secrets.

Go 392 24 27d
ghostsecurity/ skills
100%

This replaces your app sec scanners with Claude Code's AI skills.

Shell 356 17 25d
paradigmxyz/ evmbench
100%

Prevent million-dollar hacks by benchmarking AI on your smart contracts.

TypeScript 322 46 12d
GoPlusSecurity/ agentguard
100%

secures ai agents from self-sabotaging stupidity.

TypeScript 293 46 28d
sangrokjung/ claude-forge
100%

Claude Code CLI sprouts agents that run your dev workflow solo.

Shell 284 58 7d
backbay-labs/ clawdstrike
100%

tools must sign or stay leashed.

Rust 185 17 30d
spaceraccoon/ vulnerability-spoiler-alert-action
100%

ai spoils cves by spotting patches first.

TypeScript 178 22 23d
silentchainai/ SILENTCHAIN
100%

It does what Burp's passive scanner does, but with AI smarts.

Python 164 51 27d
Rench321/ sklad
100%

system tray vaults your snippets, encrypted and snappy.

TypeScript 160 2 34d
SeyZ/ clawbands
100%

This replaces your AI agent's risky tools with human approval.

TypeScript 160 14 22d
Eljakani/ ward
100%

Secures Laravel apps by decoding their structure—generic tools just skim.

Go 156 10 15d
luckyPipewrench/ pipelock
100%

Your AI agents behave when strapped into leak-proof network reins.

Go 140 6 22d
tugcantopaloglu/ openclaw-dashboard
100%

Securely oversee AI agents to control costs and catch issues instantly.

HTML 131 34 20d
clawshell/ clawshell
100%

Your keys get stunt doubles for safe LLM auditions.

Rust 127 8 17d
JaydenBeard/ clawguard
100%

monitors ai agents' mayhem with instant kill switch.

JavaScript 125 22 28d
centminmod/ explain-openclaw
100%

Your WhatsApp sprouts a private AI brain, paranoia audits included.

123 15 29d
praetorian-inc/ brutus
100%

Sweep networks for weak creds fast, zero dependencies required.

Go 121 12 18d
seojoonkim/ prompt-guard
100%

shields ai agents from sneaky prompt hijacks.

Python 105 21 32d
Trusera/ ai-bom
100%

This replaces fragmented AI tracking with complete infrastructure transparency.

Python 105 32 22d
toborrm9/ malicious_extension_sentry
100%

tracks chrome's booted bad guys daily.

HTML 104 8 30d
wardgate/ wardgate
100%

Secure AI agent API calls without exposing a single credential.

Go 102 8 27d
openclaw-rocks/ k8s-operator
100%

This replaces manual AI agent ops with production Kubernetes control.

Go 101 18 24d
1Password/ SCAM
100%

This obsoletes toy AI benchmarks with realistic workplace threat simulations.

Python 91 4 20d
softwaremill/ sandcat
100%

Your dev container proxies every outbound byte and slips in secrets undetected.

Python 91 2 19d
avast/ sage
100%

Ship AI-assisted code fearlessly with automatic guards on every tool call.

TypeScript 84 5 18d
Usta0x001/ Phantom
100%

This replaces your pentest team with autonomous AI attack chaining.

Python 83 6 10d
spaceraccoon/ vulnerability-spoiler-alert
100%

Spot OSS security patches before CVEs drop and patch your deps first.

JavaScript 79 14 20d
boostsecurityio/ bagel
100%

It audits dev workstations like enterprise scanners, but zero exfiltration.

Go 76 7 20d
fr4nsys/ usulnet
100%

Master Docker fleets across nodes from one dead-simple dashboard.

Go 75 2 21d
provos/ ironcurtain
100%

Secure AI agents with plain-English constitutions—no brittle code policies.

TypeScript 75 13 8d
mitkox/ megacode
100%

Scans massive .NET codebases for vulns that bury other tools.

Python 73 17 22d
fubak/ ferret-scan
100%

sniffs security leaks from ai cli configs.

TypeScript 73 5 30d
inkdust2021/ VibeGuard
100%

Your code chats with AI on a strict need-to-know basis.

Go 71 6 5d
sinewaveai/ agent-security-scanner-mcp
100%

Secure AI coding agents to ship vuln-free code without second-guessing.

JavaScript 71 5 26d
backslash-security/ Claw-Hunter
100%

hunts shadow ai claws before they snag your secrets.

Shell 71 6 28d
josstei/ maestro-gemini
100%

Your CLI grows an AI dev squad that plans, executes, and debugs solo.

JavaScript 68 1 21d
knostic/ openclaw-detect
100%

catches openclaw red-handed on managed devices.

Shell 66 9 28d
kadenzipfel/ scv-scan
100%

Replace manual Solidity audits with Claude's rapid vulnerability sweeps.

65 6 21d
3sk1nt4n/ cybersentinel-ai
100%

Spot threats early with AI running pro scans and decoding risks locally.

Python 61 15 19d
safedep/ gryph
100%

tracks ai coders like a suspicious spouse.

Go 60 4 32d
thecybersandeep/ graphql-grip
100%

it arms burp repeater with graphql attack payloads.

Java 57 8 32d
jrm360seclab/ aodin-vo1d-malware
100%

Someone tore open an Amazon projector and found factory botnet malware.

56 1 15d
slowmist/ openclaw-security-practice-guide
100%

This replaces brittle AI checklists with zero-trust for autonomous agents.

Shell 51 4 0d
TheGreatAzizi/ IP-Security-Analyzer-Cloudflare-Worker
100%

Every IP gets fingerprinted and its alibis shredded.

JavaScript 48 9 14d

Want daily updates on trending Security repos?

Subscribe to Weekly Digest