Agent harness 性能优化系统。为 Claude Code、Codex、Opencode、Cursor 等提供 Skill、本能、记忆、安全性与研究优先的开发能力。The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
仓库/Skill 库
190 个
面向黑客、渗透测试工程师和安全研究人员的各类精选清单合集A collection of various awesome lists for hackers, pentesters and security researchers
π RuView 将现成 WiFi 信号转化为实时空间智能、生命体征监测和存在检测,全程无需任何视频画面。π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.
开箱即用的云模板,支持 RAG、AI 流水线与企业级搜索,接入实时数据。🐳Docker 友好。⚡始终与 Sharepoint、Google Drive、S3、Kafka、PostgreSQL 以及各类实时数据 API 保持同步。Ready-to-run cloud templates for RAG, AI pipelines, and enterprise search with live data. 🐳Docker-friendly.⚡Always in sync with Sharepoint, Google Drive, S3, Kafka, PostgreSQL, real-time data APIs, and more.
精选 Docker 资源与项目列表:whale: A curated list of Docker resources and projects
OpenClaw 的轻量级替代方案,在容器中运行以保障安全。可连接 WhatsApp、Telegram、Slack、Discord、Gmail 等消息应用,具备 memory、定时任务能力,直接基于 Anthropic Agents SDK 运行。A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
为 AI agents 提供 817 项结构化网络安全技能 · 映射至 6 个框架:MITRE ATT&CK、NIST CSF 2.0、MITRE ATLAS、D3FEND、NIST AI RMF 与 MITRE F3(Fight Fraud)· 采用 agentskills.io 标准 · 兼容 Claude Code、GitHub Copilot、Codex CLI、Cursor、Gemini CLI 及 20+ 平台 · 覆盖 29 个安全领域 · Apache 2.0817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
开源 agentic AI 数据助手,面向下一代 AI + Data 产品。open-source agentic AI data assistant for the next generation of AI + Data products.
该开源课程通过 .NET、Java、TypeScript、JavaScript、Rust 和 Python 等跨语言真实案例,介绍 Model Context Protocol (MCP) 的基础知识。面向开发者,聚焦从会话建立到服务编排的模块化、可扩展且安全的 AI 工作流实践技巧。This open-source curriculum introduces the fundamentals of Model Context Protocol (MCP) through real-world, cross-language examples in .NET, Java, TypeScript, JavaScript, Rust and Python. Designed for developers, it focuses on practical techniques for building modular, scalable, and secure AI workflows from session setup to service orchestration.
AI Agent skill 的安全扫描器。在安装 Claude Code、Codex 和 MCP skill 之前,检测其中的漏洞、恶意模式、安全风险、prompt injection、数据外泄以及供应链风险。Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
在 Windows 11 中强制移除 Copilot、Recall 等组件Force Remove Copilot, Recall and More in Windows 11
HexStrike AI MCP Agents 是一个高级 MCP 服务器,让 AI agent(Claude、GPT、Copilot 等)能够自主运行 150+ 网络安全工具,用于自动化渗透测试、漏洞发现、漏洞赏金自动化和安全研究,无缝桥接 LLM 与真实世界的攻击性安全能力。HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
开源免费——历经阿里巴巴规模实战检验。混合架构代码审查工具:确定性流水线 + LLM Agent,精确的逐行注释,内置微调规则集(NPE、线程安全、XSS、SQL 注入),兼容 OpenAI 与 Anthropic。Open-source & free — Battle-tested at Alibaba's scale. Hybrid architecture code review tool: deterministic pipelines + LLM Agent, precise line-level comments, built-in fine-tuned ruleset (NPE, thread-safety, XSS, SQL injection), OpenAI & Anthropic compatible.
Astrid:面向可组合软件的轻量级、能力安全(capability-secure)操作系统。Astrid is a portable, capability-secure operating system for composable software.
Cybersecurity AI (CAI),面向 AI 安全的框架。Cybersecurity AI (CAI), the framework for AI Security
OpenAI 的 Codex Security CLI 与 TypeScript SDK,用于发现、验证和修复安全漏洞。npm: https://www.npmjs.com/package/@openai/codex-securityOpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Astrid OS 的权威参考:内核、capsules、host ABI、总线与安全模型。The canonical reference for Astrid OS: kernel, capsules, host ABI, the bus, and the security model. Part of Unicity Astrid OS.
Astrid 的权威参考:内核、capsules、host ABI、IPC 和安全模型。The canonical reference for Astrid: kernel, capsules, host ABI, IPC, and the security model.
提供威胁建模、扫描、分诊、修补等技能,以及一个可通过 /customize 定制的自主扫描 harness。Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
AI Agent 治理工具包 —— 提供策略执行、零信任身份、运行沙箱与可靠性工程,覆盖 OWASP Agentic Top 10 全部 10 项。AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
AI 原生网络安全的执行系统——意图转化为受治理的执行,证据成为可运营的记忆,每一次操作都让下一次更优。The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
🐢 面向 LLM Agent 的开源评估与测试库🐢 Open-Source Evaluation & Testing library for LLM Agents
自主红队平台;多 Agent 攻击性安全元框架autonomous red teaming platform; multi-agent offensive-security meta-harness
A Codex jailbreak prompt and test pack for gpt-5.6-sol. 针对 gpt-5.6 系列的 Codex 破甲提示词与测试包。
用于检查磁盘上 package、extension 与开发者工具元数据暴露面的只读开发者端点扫描器,旨在排查已知的软件供应链攻击。Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
面向 AI Agent 的开发者控制平面Developer Control Plane for your AI Agents
:orange_book: 面向 Offensive Security OSCP、OSWE、OSCE、OSEE、OSWP 考试报告的 Markdown 模板:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report
独立 iOS 应用,可在无需越狱的情况下模拟 GPS 定位。包含 Shadowrocket/Surge/Loon/QX/Stash 模块。Standalone iOS app to spoof GPS location without jailbreak. Includes Shadowrocket/Surge/Loon/QX/Stash module.
claude-red 是一个面向 Claude skills 系统的进攻性安全 skill 精选库。每个 skill 都是一个结构化的 SKILL.md 文件,为 Claude 注入针对特定攻击面的专家级方法论 — 涵盖 SQLi、shellcode、EDR 规避到漏洞利用开发等。claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
100+ 可安装的 Claude skill,覆盖工程领域,包括 ISO 26262 功能安全、ISO/SAE 21434 网络安全、ISO 21448 SOTIF、AIAG-VDA 质量(APQP/PPAP/FMEA)、Automotive SPICE 及持续改进工具 — 每个构建 skill 均配有一个确认 reviewer。100+ installable Claude skills covering Engineering areas such as, ISO 26262 functional safety, ISO/SAE 21434 cybersecurity, ISO 21448 SOTIF, AIAG-VDA quality (APQP/PPAP/FMEA), Automotive SPICE, and continuous improvement tools — every builder paired with a confirmation reviewer.
8 个 Claude Skill · 100+ 侦察能力 · 80 条 secret-regex 模式 · 80+ dorks · 9 个只读凭据验证器 · 27 个攻击路径模板 · 约 10,000 行结构化技术内容。开箱即用的 SKILL.md 文件,可将 Claude 改造为面向授权红队与漏洞赏金项目的顶级外部侦察操作员。8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bounty engagements.
ToolHive是用于运行和管理MCP服务器的企业级平台ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.
WFGY 正迈向 WFGY 5.0 Polaris Protocol,面向 AI reasoning、RAG、agents 与真实工作流的重要开源版本,包含 Problem Map、Global Debug Card、WFGY 4.0 与 CFV Easter EggWFGY is heading toward WFGY 5.0 Polaris Protocol, a major open-source release for AI reasoning, RAG, agents, and real-world workflows. Includes Problem Map, Global Debug Card, WFGY 4.0, and the CFV Easter Egg.
开源自托管的 AI 漏洞研究工具,通过编排 Agent 发现并验证代码中的安全问题。Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.