Open source ai-security projects

Every project in the registry tagged ai-security, ranked by real GitHub adoption.

projects 26 combined stars ★ 187K refresh nightly
01 strix ★ 63K

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

last push4 hours ago languagePython licenseApache-2.0
02 shannon ★ 48K

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabi

last push9 days ago languageTypeScript licenseAGPL-3.0
03 SkillSpector ★ 18K

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in

last push4 hours ago languagePython licenseApache-2.0
04 codex-security ★ 11K

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-se

last push5 hours ago languageTypeScript licenseApache-2.0
05 AI-Infra-Guard ★ 6.4K

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

last push15 hours ago languagePython licenseApache-2.0
06 giskard-oss ★ 5.8K

🐢 Open-Source Evaluation & Testing library for LLM Agents

last push38 hours ago languagePython licenseApache-2.0
07 Agentic-Bug-Hunter ★ 4.9K

AI-powered bug bounty hunting toolkit that works with or without subscription.

last push18 hours ago languagePython licenseMIT
08 nono ★ 4.1K

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

last push8 hours ago languageRust licenseApache-2.0
09 CyberStrike ★ 2.8K

Open-source AI-powered offensive security harness for automated penetration testing.

last push8 hours ago languageTypeScript licenseAGPL-3.0
10 AiSOC ★ 2.4K

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-host

last push4 days ago languagePython licenseMIT
11 pentest-ai-agents ★ 2.2K

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, r

last push1 months ago languageShell licenseMIT
12 toolhive ★ 2.2K

ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.

last push5 hours ago languageGo licenseApache-2.0
13 open-kritt ★ 2.1K

Open-source, self-hosted AI vulnerability research tool that orchestrates agents to find and validate security issues in code.

last push2 days ago languageJavaScript licenseAGPL-3.0
14 pentest-ai ★ 1.7K

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

last push5 days ago languagePython licenseMIT
15 ADR ★ 1.6K

ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.

last push31 hours ago languagePython licenseApache-2.0
16 akto ★ 1.5K

Akto is the fastest growing AI Security platform for your teams to secure AI agents, MCPs, LLMs, Agent skills, Gen AI apps in your organization.

last push6 hours ago languageJava licenseMIT
17 stride-gpt ★ 1.1K

An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.

last push3 days ago languagePython licenseMIT
18 xalgorix ★ 1.1K

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

last push2 days ago languageGo licenseApache-2.0
19 agentic-radar ★ 1.1K

A security scanner for your LLM agentic workflows

last push10 months ago languagePython licenseApache-2.0
20 reconmap ★ 981

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance throu

last push4 days ago languageJavaScript licenseApache-2.0
21 vuln-bank ★ 933

A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features com

last push6 days ago languageHTML licenseMIT
22 pipelock ★ 879

Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injecti

last push4 hours ago languageGo licenseApache-2.0
23 ship-safe ★ 844

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API

last push2 days ago languageJavaScript licenseMIT
24 api-relay-audit ★ 839

Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web

last push38 hours ago languagePython licenseAGPL-3.0
25 arcjet-js ★ 683

Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop

last push9 hours ago languageTypeScript licenseApache-2.0
26 Adrian ★ 566

Open-source runtime AI agent security tool - monitors and controls AI agents, catching malicious tool use, prompt injection, and policy drift in real time, befo

last push2 days ago languagePython licenseApache-2.0

Related tags

← all tags

Frequently asked questions

How many open source ai-security projects are there?

This registry tracks 26 projects tagged ai-security, with 186,551 GitHub stars between them. The most-adopted is strix at 63,281 stars.

Are these ai-security projects free to use?

Yes — 26 of the 26 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which ai-security project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these ai-security projects still maintained?

25 of the 26 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.