WFGY 正迈向 WFGY 5.0 Polaris Protocol,面向 AI reasoning、RAG、agents 与真实工作流的重要开源版本,包含 Problem Map、Global Debug Card、WFGY 4.0 与 CFV Easter EggWFGY is heading toward WFGY 5.0 Polaris Protocol, a major open-source release for AI reasoning, RAG, agents, and real-world workflows. Includes Problem Map, Global Debug Card, WFGY 4.0, and the CFV Easter Egg.
仓库/Skill 库
242 个
开源自托管的 AI 漏洞研究工具,通过编排 Agent 发现并验证代码中的安全问题。Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.
ADR 通过可观测性、安全基准测试与威胁检测,为企业级 AI Agent 提供安全保障。已部署于 Uber。ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
面向攻击性安全的 MCP server,封装 205 个工具、17 个专家 agent 和 60 个 SPA 感知探针,覆盖 OWASP Top 10。支持 CLI + MCP,可自带 LLM,MCP 路径无需 API key。Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
🤖 面向 AI agent 的本地辅助 BOSS 直聘 CLI,支持搜索、福利筛选、生成候选名单、JSON 信封输出,默认低风险且合规。🤖 Local-assist BOSS Zhipin CLI for AI agents — search, welfare filtering, shortlist, JSON-envelope output; low-risk & compliant by default.
社区最全面、持续更新的 LLM 软件漏洞检测研究索引——涵盖函数级、仓库级、Agent 级以及智能合约检测方向的论文,并附数据集、基准和综述The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers across function-level, repository-level, agentic, and smart-contract detection, plus datasets, benchmarks, and surveys.
[EMNLP 2024 Demo] MarkLLM:面向 LLM 水印的开源工具包[EMNLP 2024 Demo] MarkLLM: An Open-Source Toolkit for LLM Watermarking
阻止你的 AI 胡编乱造——AI 提出方案,确定性工具做决策,每条断言都对照真实证据进行核验。可信事实与上下文在重置后仍能保留。逆向工程作为验证场。MCP server + CLI。Stop your AI from making things up — it proposes, deterministic tools decide, every claim checked against ground truth with evidence. Grounded facts and context survive resets. Reverse engineering is the proving ground. MCP server + CLI.
开源 AI agent 防火墙,用于 MCP 安全与 agent 出站流量防护。扫描经中介的 HTTP、MCP、A2A 与 WebSocket 流量,检测数据外泄、SSRF 与 prompt 注入,并签发由中介签名的操作回执:在 agent 之外生成可验证的审计证据。Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.
通过统一的基于 SQL 的框架,为人类和 AI Agent 提供 Cloud、SaaS、API 和 Model Context Protocol (MCP) 资源的查询、配给与运维能力。Query, provision and operate Cloud, SaaS, API and Model Context Protocol (MCP) resources through a unified SQL-based framework for humans and AI agents.
面向治理、风险与合规(GRC)的 Claude Skills:针对 ISO 27001、SOC 2、FedRAMP、GDPR、HIPAA、NIST CSF、PCI DSS、EU AI Act、ISO 42001、ISO 27701、DORA、CSRD、印度 DPDPA、CMMC 2.0、NIST AI Risk、SWIFT、澳大利亚 ISM、EU NIS2、CCPA/CPRA 等的专家级合规指导。使用 skills 基准 97%,不使用 81%。Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, Australia's ISM, EU NIS2, CCPA/CPRA, and others. Benchmark 97% (with skills) vs 81% (without skills).
面向机器操作的 consequence firewall。EMILIA Gate 在资金、代码、权限、基础设施或受监管状态变更前校验确切授权;其开放协议使证据可独立验证。Consequence firewall for machine actions. EMILIA Gate verifies exact authority before money, code, permissions, infrastructure, or regulated state changes; the open protocol makes the evidence independently verifiable.
claude-red 是一个面向 Claude skills 系统策划的攻击性安全 skills 库。每个 skill 是一个结构化的 SKILL.md 文件,为 Claude 提供针对特定攻击面的专家级方法论,涵盖从 SQLi 到 shellcode、EDR 规避到漏洞利用开发。claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
基于 Hermes Agent 的自主攻击性安全、漏洞悬赏与红队 Agent 框架,具备专用推理技能与多模型 LLM 编排能力。Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
面向 AI agent 和 API 的执行授权网关。它拦截关键 HTTP 操作,向 Decionis 请求授权判断,并在一次性授权下精确转发、留待人工处理或拒绝请求,同时为每次操作留下链式证据。可通过 Homebrew、Linux 包、Docker 或 Helm 安装。An execution-authority gateway for AI agents and APIs. It intercepts consequential HTTP actions, asks Decionis whether they are authorized, and forwards exactly the authorized request once on a single-use grant, holds it for a person, or refuses it, leaving chained evidence of each. Installs by Homebrew, Linux package, Docker or Helm.
AI 工程课程:一套免费且完整的 AI 工程课程,循序渐进地学习 AI 工程——涵盖机器学习、神经网络、Transformer、LLM、微调、RAG、AI Agents、LLM 推理、评估、AI 安全与 AI 系统设计。AI Engineering Course - A free and complete AI Engineering Course to learn AI Engineering step by step - from Machine Learning, Neural Networks, and Transformers to LLMs, Fine-Tuning, RAG, AI Agents, LLM Inference, Evaluation, AI Safety, and AI System Design.
一个面向英文学术写作的保守型 AIGC 检测器指导的论文改写 Skill。支持 Turnitin AI、CNKI AIGC、最小化编辑修订、保留学术要素、定性/定量路由,以及逐章降低 AI 写作风险,且不宣称绕过检测器。A conservative AIGC detector-informed thesis rewriting skill for English and Chinese academic writing. Supports Turnitin AI, CNKI AIGC, minimal-edit revision, protected academic elements, qualitative/quantitative routing, and chapter-by-chapter AI-writing risk reduction without detector-bypass claims.
一款 MCP,让 AI 工具安全连接基础设施、编写 IaaS 代码、调试问题并在故障中提供协助,且不危及生产稳定性。专为安全团队审批而设计,为基础设施团队带来如魔法般的体验。An MCP that lets AI tools securely connect to your infrastructure, write IaaS code, debug issues, and assist during incidents - without risking production stability. Built for security teams to approve and infrastructure teams to experience like magic.
Vibe-Coding 容易,DevOps 难。OpenCode 与 Git 为你的应用、业务和个人开发提供 token 高效的 AI agent 自动化。提供面向速度、安全性与 7×24 持续运行的强约定工具、服务、CLI 与 API 栈。开源优先,全面 SOTA。GitHub 协作与团队工作的最佳 AI harness。Vibe-Coding is easy. DevOps is hard. OpenCode & Git token-efficient AI agent automation for your app, business, and personal development. Opinionated tools, services, CLI & API stack for speed, security, and 24/7 results. Open-source first. SOTA everything. The best AI harness for GitHub & teamwork.
白箱AGI架构探索:元认知(自我认知循环)、持续学习(知识飞轮)、世界模型(条件空间+语义时空图)、自我改进(自举纪律)、零LLM白箱管线与可审计信任护栏。
自托管、兼容 OpenAI 的 AI 网关,用于私有 RAG、自然语言数据访问和工具调用 AgentSelf-hosted, OpenAI-compatible AI gateway for private RAG, natural-language data access, and tool-calling agents.
🛡️ AI agents 的审批与策略层。在高风险动作执行前进行拦截、阻断或远程审批。🛡️ The approval and policy layer for AI agents. Intercept risky actions before they run, block them, or approve them remotely.
Claude Code 的完整 AI 开发工具包。包含 106 个 skill、36 个 agent、171 个 hook。安装 `ork` 获取稳定版(v9.x),或安装 `ork-alpha` 获取每日发布的 v10 版本。The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stable (v9.x), or `ork-alpha` for the v10 line, which ships daily.
DeepSeek Harness 审批请求的 second-model AI 自动复核:只读复核子 Agent 返回结构化 allow/deny 判定及理由,默认 fail-closed,会话日志(approval/asked → autoReview/verdict → approval/decided)全程可审计。Second-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default, fully auditable from the session log (approval/asked -> autoReview/verdict -> approval/decided).
ARTEX 韩语版 · AI 自主渗透测试框架本地化(上游:Autumn-27/ARTEX,AGPL-3.0)ARTEX 한국어판 · AI 자율 침투 테스트 프레임워크 현지화 (upstream: Autumn-27/ARTEX, AGPL-3.0)
AgenticX 是一个统一、生产就绪的多 Agent 平台——Python SDK + CLI (agx) + Studio server + Machi 桌面应用。具备 Meta-Agent 编排、15+ LLM provider、MCP Hub、分层记忆、头像与群聊、Skill 生态、安全沙箱和 IM 网关(飞书/微信)。AgenticX is a unified, production-ready multi-agent platform — Python SDK + CLI (agx) + Studio server + Machi desktop app. Features Meta-Agent orchestration, 15+ LLM providers, MCP Hub, hierarchical memory, avatar & group chat, skill ecosystem, safety sandbox, and IM gateway (Feishu/WeChat).
一份配置即可统管所有 AI agents:跨项目跨会话可移植、内置精选写作/路由/skills、更安全(内置破坏性命令防护)One config to rule all your AI agents: portable (every project, every session), effective (curated writing, routing, skills), and safer (destructive-command guard).
用于 AML/KYT 审查的多链加密钱包风险扫描器。基于制裁名单、风险合约与资金追溯为地址打 0–100 分。集成 6 家情报源并支持故障转移,可识别骗局、黑客攻击、混币器与钓鱼攻击,支持 15+ 链、批量扫描及 TXT/JSON/CSV/HTML/PDF 报告。Python 实现,跨平台。Multi-chain crypto wallet risk scanner for AML/KYT screening. Scores addresses 0–100 using sanctions, risky contracts and fund tracing. Integrates 6 intelligence providers with failover, detects scams, hacks, mixers and phishing, supports 15+ chains, batch screening and TXT/JSON/CSV/HTML/PDF reports. Python, cross-platform.
面向 OpenAI Codex CLI 的自治系统与安全工具集。确定性二进制分析、解耦流水线与零摩擦执行。Autonomous Systems & Security Toolkit for OpenAI Codex CLI. Deterministic binary analysis, decoupled pipeline, and zero-friction execution.
面向 Polymarket 预测市场的交易机器人——浏览 CLOB 市场、在终端查看订单簿、运行套利检测、流动性提供与跨市场套利策略,支持模拟交易和风险限额。教育性开源工具包——不构成投资建议。非官方社区项目,与 Polymarket 无关。Polymarket trading bot for prediction markets — browse CLOB markets, watch the order book in the terminal, run edge detection, liquidity provision and cross-market arbitrage strategies with paper trading and risk limits. Educational open-source toolkit — not financial advice. Unofficial community project, not affiliated with Polymarket.
面向自主 agent 的企业级 gateway,提供身份管理、按通道隔离、凭据 vault、按会话防篡改审计日志。The enterprise gateway for autonomous agents. Identity management, per-channel isolation, credential vault, per-session tamper-evident audit log.
本综述目标有二:(i) 综述对抗机器学习(AML)在推荐系统(RS)安全上的最新进展,即攻击与防御推荐模型;(ii) 展示 AML 在生成对抗网络(GAN)生成应用中的成功应用,得益于其学习(高维)数据分布的能力。本文对发表于主流 RS 与 ML 期刊会议的 74 篇文献进行了详尽综述,可作为 RS 社区在推荐系统安全及利用 GAN 提升生成模型质量方面的参考The goal of this survey is two-fold: (i) to present recent advances on adversarial machine learning (AML) for the security of RS (i.e., attacking and defense recommendation models), (ii) to show another successful application of AML in generative adversarial networks (GANs) for generative applications, thanks to their ability for learning (high-dimensional) data distributions. In this survey, we provide an exhaustive literature review of 74 articles published in major RS and ML journals and conferences. This review serves as a reference for the RS community, working on the security of RS or on generative models using GANs to improve their quality.
在 Minimal 沙箱中运行你的 Agent。在自己的电脑上以隔离方式发布和运行软件。Run your agent in a Minimal box. Ship and run software with isolation on your own computer.