AI agents for pentesting, code audit, fuzzing, vulnerability discovery, and reverse engineering — harnesses, sandboxes, security MCP servers, benchmarks, and evals.
AI agents for pentesting, code audit, fuzzing, vulnerability discovery, and reverse engineering — harnesses, sandboxes, security MCP servers, benchmarks, and evals.
Please read the contribution guidelines before opening a pull request.
- What Is a Security Agent Harness - Code Audit Harnesses - Pentesting Agents - Fuzzing and Vulnerability Discovery - Reverse Engineering Agents - Agent Sandboxes - Benchmarks and Evals
A security agent harness is everything wrapped around the model: the sandbox it runs in, the analysis tools it can call, the prompts and skills that encode a methodology, and the evals you use to check it. Most of the engineering in these systems lives here rather than in the model.
Agents are good at producing plausible findings and bad at telling which ones are real. A harness that can reproduce a crash, replay an input, or re-run a static analyzer is how you throw out the bad ones before a human ever sees them.
Harnesses that run coding agents against source code: discovery, triage, validation, and patching.
- Codex Security - OpenAI's CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities with Codex. - Deepsec - Vercel Labs' security harness for finding vulnerabilities in a codebase using coding agents. - Defending Code Reference Harness - Anthropic's reference implementation for autonomous vulnerability discovery and remediation with Claude, with skills for threat modeling, scanning, triage, and patching. - Visa Vulnerability Agentic Harness - Visa's agentic SAST pipeline for autonomous vulnerability discovery, remediati
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/Ed-Marcavage--awesome-security-agent-harnesses.html)
A curated list of awesome agentic commerce resources — protocols, MCP servers, tools, apps, APIs and services for AI agents that shop, sell and transact. For store owners, developers, agencies and mar
flankerhqd/cyvisguardSecurity control plane for AI agents — identity and delegation, capability policy, data-flow taint and a live audit trail, enforced over MCP. Guards a real Claude Code end to end.
howshannon/trust-issuesAdversarial security review for AI skills, repos, MCP servers, and packages before you install them. A read-only scanner plus a five-persona reasoning pass, ending in a GO / GO WITH MITIGATIONS / NO-G
brycewang-stanford/lit-review-agent-tools🤖 The strongest curated list of open-source AI-agent tools for literature review — 70+ tools across 11 categories (Claude Code skills, deep research, MCP servers, PDF parsing, systematic review). 面向智能
yagyeshVyas/VibeGuardFree security & privacy scanner for AI-coded apps. 699 rules, 76 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your AI-generated app for l
Kota-Karthik/secure-actionsMCP server for secure AI agent authentication — lets Claude, Claude Code, and other LLM agents call APIs without exposing raw tokens or credentials to the model
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.