面向攻击性安全的 MCP server,封装 205 个工具、17 个专家 agent 和 60 个 SPA 感知探针,覆盖 OWASP Top 10。支持 CLI + MCP,可自带 LLM,MCP 路径无需 API key。Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.
仓库/Skill 库
190 个
🤖 面向 AI agent 的本地辅助 BOSS 直聘 CLI,支持搜索、福利筛选、生成候选名单、JSON 信封输出,默认低风险且合规。🤖 Local-assist BOSS Zhipin CLI for AI agents — search, welfare filtering, shortlist, JSON-envelope output; low-risk & compliant by default.
社区最全面、持续更新的 LLM 软件漏洞检测研究索引——涵盖函数级、仓库级、Agent 级以及智能合约检测方向的论文,并附数据集、基准和综述The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers across function-level, repository-level, agentic, and smart-contract detection, plus datasets, benchmarks, and surveys.
面向治理、风险与合规(GRC)的 Claude Skills:针对 ISO 27001、SOC 2、FedRAMP、GDPR、HIPAA、NIST CSF、PCI DSS、EU AI Act、ISO 42001、ISO 27701、DORA、CSRD、印度 DPDPA、CMMC 2.0、NIST AI Risk、SWIFT、澳大利亚 ISM、EU NIS2、CCPA/CPRA 等的专家级合规指导。使用 skills 基准 97%,不使用 81%。Claude Skills for Governance, Risk, & Compliance (GRC): Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, EU AI Act, ISO 42001, ISO 27701, DORA, CSRD, India's DPDPA, CMMC 2.0, NIST AI Risk, SWIFT, Australia's ISM, EU NIS2, CCPA/CPRA, and others. Benchmark 97% (with skills) vs 81% (without skills).
面向机器操作的 consequence firewall。EMILIA Gate 在资金、代码、权限、基础设施或受监管状态变更前校验确切授权;其开放协议使证据可独立验证。Consequence firewall for machine actions. EMILIA Gate verifies exact authority before money, code, permissions, infrastructure, or regulated state changes; the open protocol makes the evidence independently verifiable.
claude-red 是一个面向 Claude skills 系统策划的攻击性安全 skills 库。每个 skill 是一个结构化的 SKILL.md 文件,为 Claude 提供针对特定攻击面的专家级方法论,涵盖从 SQLi 到 shellcode、EDR 规避到漏洞利用开发。claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
一个面向英文学术写作的保守型 AIGC 检测器指导的论文改写 Skill。支持 Turnitin AI、CNKI AIGC、最小化编辑修订、保留学术要素、定性/定量路由,以及逐章降低 AI 写作风险,且不宣称绕过检测器。A conservative AIGC detector-informed thesis rewriting skill for English and Chinese academic writing. Supports Turnitin AI, CNKI AIGC, minimal-edit revision, protected academic elements, qualitative/quantitative routing, and chapter-by-chapter AI-writing risk reduction without detector-bypass claims.
一款 MCP,让 AI 工具安全连接基础设施、编写 IaaS 代码、调试问题并在故障中提供协助,且不危及生产稳定性。专为安全团队审批而设计,为基础设施团队带来如魔法般的体验。An MCP that lets AI tools securely connect to your infrastructure, write IaaS code, debug issues, and assist during incidents - without risking production stability. Built for security teams to approve and infrastructure teams to experience like magic.
Vibe-Coding 很简单,DevOps 很难。OpenCode 与 Git 的 token 高效 AI agent 自动化,面向应用、商业和个人开发。面向速度、安全性和 7×24 效果的强势工具、服务、CLI 和 API 技术栈。开源优先,处处 SOTA。在你的仓库上试用,体验赚钱魔力。Vibe-Coding is easy. DevOps is hard. OpenCode & Git token-efficient AI agent automation for your app, business, and personal development. Opinionated tools, services, CLI & API stack for speed, security, and 24/7 results. Open-source first. SOTA everything. Try on your repos for money-making magic.
Claude Code 的完整 AI 开发工具包。包含 106 个 skill、36 个 agent、171 个 hook。安装 `ork` 获取稳定版(v9.x),或安装 `ork-alpha` 获取每日发布的 v10 版本。The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stable (v9.x), or `ork-alpha` for the v10 line, which ships daily.
一份配置即可统管所有 AI agents:跨项目跨会话可移植、内置精选写作/路由/skills、更安全(内置破坏性命令防护)One config to rule all your AI agents: portable (every project, every session), effective (curated writing, routing, skills), and safer (destructive-command guard).
基于 Hermes Agent 的自主攻击性安全、漏洞悬赏与红队 Agent 框架,具备专用推理技能与多模型 LLM 编排能力。Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
AgenticX 是一个统一、生产就绪的多 Agent 平台——Python SDK + CLI (agx) + Studio server + Machi 桌面应用。具备 Meta-Agent 编排、15+ LLM provider、MCP Hub、分层记忆、头像与群聊、Skill 生态、安全沙箱和 IM 网关(飞书/微信)。AgenticX is a unified, production-ready multi-agent platform — Python SDK + CLI (agx) + Studio server + Machi desktop app. Features Meta-Agent orchestration, 15+ LLM providers, MCP Hub, hierarchical memory, avatar & group chat, skill ecosystem, safety sandbox, and IM gateway (Feishu/WeChat).
本综述目标有二:(i) 综述对抗机器学习(AML)在推荐系统(RS)安全上的最新进展,即攻击与防御推荐模型;(ii) 展示 AML 在生成对抗网络(GAN)生成应用中的成功应用,得益于其学习(高维)数据分布的能力。本文对发表于主流 RS 与 ML 期刊会议的 74 篇文献进行了详尽综述,可作为 RS 社区在推荐系统安全及利用 GAN 提升生成模型质量方面的参考The goal of this survey is two-fold: (i) to present recent advances on adversarial machine learning (AML) for the security of RS (i.e., attacking and defense recommendation models), (ii) to show another successful application of AML in generative adversarial networks (GANs) for generative applications, thanks to their ability for learning (high-dimensional) data distributions. In this survey, we provide an exhaustive literature review of 74 articles published in major RS and ML journals and conferences. This review serves as a reference for the RS community, working on the security of RS or on generative models using GANs to improve their quality.
Apeireth——AGI 操作系统 / LLM 基础(Rust)。85 个 crate:companion organ、world model、好奇心、假设检验、双层洋葱安全。Apeireth — An AGI Operating System / LLM Base (Rust). 85 crates: companion organ, world model, curiosity, hypothesis testing, double-onion security.
AI 编码 Agent 的资深开发者纪律:未勾选即视为失败的提交门禁、拒绝将未完成工作标记为完成的质量控制器,以及闭环每类逃逸缺陷的经验循环。单一 Go 二进制,无运行时依赖,兼容 20+ AgentSenior-developer discipline for AI coding agents. A commit gate that counts unchecked as failing, quality controllers that refuse to call unfinished work done, and a lessons loop that closes each escaped bug's class. One Go binary, no runtime deps, works with 20+ agents.
Promptfoo 的 GitHub Action。可用于测试 prompt、Agent 与 RAG;支持 LLM 的 AI 红队对抗、渗透测试与漏洞扫描;对比 GPT、Claude、Gemini、Llama 等模型的性能;通过简洁的声明式配置集成命令行与 CI/CD。The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.
真实 AI Agent 安全事件、入侵和漏洞的精选时间线(2024-2026)。每条记录均标注来源和日期。A curated timeline of real AI agent security incidents, breaches, and vulnerabilities (2024-2026). Every entry sourced and dated.
Apeireth——一款基于 Rust 的 AGI 操作系统 / LLM 基座。85 个 crate:陪伴器官、世界模型、好奇心、假设检验、双层洋葱式安全Apeireth — An AGI Operating System / LLM Base (Rust). 85 crates: companion organ, world model, curiosity, hypothesis testing, double-onion security.
开源 FDE Agent 与企业 AI 约束层:24 条规则的 git-diff 审计、自动快照回滚、规则注入、自我进化。以 9 个 DeepSeek Harness 插件 + MCP server(66 个工具)形式交付。MIT 许可。Open-source FDE Agent & constraint layer for enterprise AI: 24-rule git-diff audit, auto snapshot rollback, rule injection, self-evolution. Ships as 9 DeepSeek Harness plugins + MCP server (66 tools). MIT.
面向创意工具的 Skill 优先控制平面:共享 MCP/REST runtime、gateway、CLI、marketplace、安全与可观测性,覆盖工作室流水线。Skill-first control plane for creative tools: shared MCP/REST runtime, gateway, CLI, marketplace, safety, and observability across studio pipelines.
面向 coding agent 的本地护栏机制:策略、审批、86 个安全策略包、操作系统级沙箱、审计追踪,无需 Docker。Local guardrails for coding agents. Policy, approvals, 86 safety packs, OS sandbox, audit trail — no Docker.
面向 AI Agent 的 Metasploit:扫描、攻击并修复 AI Agent 与 MCP 服务器。开源安全工具包Metasploit for AI agents: scan, attack, and fix AI agents and MCP servers. Open source security toolkit.
SPY put-credit 验证与真金白银的 control plane,具备券商账本支持、确定性 risk gates、hybrid RAG、对账及每月 $1k 税后收益证据追踪。SPY put-credit validation and real-money control plane with broker-backed ledgers, deterministic risk gates, hybrid RAG, reconciliation, and $1k/mo after-tax evidence tracking.
grantex 是面向 AI Agent 的身份、授权与审计基础设施,堪称 Agentic 互联网的"OAuth 时刻"。提供通用 SDK 与云服务,让任意 AI Agent 可代表人类在限定、可撤销权限下执行操作,并具备加密身份与不可篡改的审计追踪。开发者可在数分钟内完成集成。grantex is the identity, authorization, and audit infrastructure for AI agents — the "OAuth moment" for the agentic internet. We provide a universal SDK and cloud service that lets any AI agent act on behalf of a human with scoped, revocable permissions, cryptographic identity, and an immutable audit trail. Developers integrate in minutes.
DeepSeek AI 官方 DeepSeek Harness (dsh) 的独立、基于源码的 handbook:覆盖 Agent、插件、安全、故障排查与 runbook。Independent, source-backed handbook for DeepSeek AI's official DeepSeek Harness (dsh): agents, plugins, security, troubleshooting, and runbooks.
ThumbGate 预动作检查通过排序后的教训和反复失败进行自我改进,硬性阻断检测到的密钥泄露,并在严格模式下阻断匹配项。ThumbGate Pre-Action Checks self-improve from ranked lessons and repeated failures, hard-block detected secret leaks, and block matches in strict mode.
一个以证据为引领的六语种 LLM 实战手册:包含可迁移的核心、Codex 旗舰路线,以及 ChatGPT、Claude Code、Gemini、DeepSeek 和 Grok 的适配器。An evidence-led, six-language LLM playbook: the transferable core, the Codex flagship track, and adapters for ChatGPT, Claude Code, Gemini, DeepSeek, and Grok.
用于评估 Agentic AI 应用的 AI 红队工具与 LLM 安全框架,测试 prompt injection,支持漏洞评估、SBOM 生成与静态分析。AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.
EnterpriseRAG-AI:面向 AI Agent 工作负载的 Linux 原生、eBPF 驱动的安全与治理网格。EnterpriseRAG-AI: The Linux-Native, eBPF-Powered Security & Governance Mesh for AI Agent Workloads
面向行情录制、交易安全与可复现研究的工程工具包。多交易所 kill-switch、带钱包标签的 Hyperliquid 微结构录制器、资金费率 carry 研究栈。Engineering toolkit for market-data recording, execution safety and reproducible research. Multi-exchange kill-switch, wallet-tagged Hyperliquid microstructure recorder, funding-carry research stack.
rust-in-peace——面向 Rust 的 agentic 安全审查:自主发现/分类/修复 unsafe/FFI 内存缺陷、panic-DoS 与反序列化信任缺陷(Miri / sanitizer / panic / hang detectors)。rust-in-peace 是 anthropics/defending-code-reference-harness 的 Rust 安全分支。rust-in-peace — agentic security review for Rust: autonomous find/triage/patch for unsafe/FFI memory bugs, panic-DoS, and deserialization-trust flaws (Miri / sanitizer / panic / hang detectors). A Rust-security fork of anthropics/defending-code-reference-harness.
面向 Agent 时代的供应链攻击扫描器。使用 `npx patient-zero` 在 30 秒内完成 triage,在 postinstall 执行前拦截恶意安装,也可作为 GitHub Action 接入 CI。覆盖 npm + Python + MCP agent 配置。免费、MIT、无需注册、无遥测。Supply-chain attack scanner for the agent era. Triage in 30s with `npx patient-zero`, block malicious installs before postinstall runs, or drop into CI as a GitHub Action. Covers npm + Python + MCP agent configs. Free, MIT, no signup, no telemetry.
数据在本地自由探索 —— AI Agent 受控运行。具备治理化 Agent 访问能力的联邦化数据探索器。Your data, explored locally — and your AI agents kept on a leash. A federated data explorer with governed agentic access.
面向 Node.js 与 TypeScript 的 AI firewall。阻止 prompt injection、音频幻觉与 RAG 数据爬取。零依赖。MIT 许可。AI firewall for Node.js & TypeScript. Stop prompt injection, audio hallucinations, and RAG data scraping. Zero dependencies. MIT