Open Source Security Projects
Discover 166 open source Security repositories from GitHub, each with an analysis of what it does, key features, use cases and alternatives. Security projects here are most often combined with Self Hosted, Python and AI Agents. Last updated October 4, 2026.
166 repositories · updated October 4, 2026

apkstudio: Decompile and Edit Android APKs
APK Studio is a Qt-based desktop IDE for inspecting and modifying Android application packages. It brings APK decompilation, code and resource viewing, rebuilding, signing, and installation into one cross-platform workflow.

mullvadvpn-app: Secure VPN Client for Desktop and Mobile
Mullvad VPN’s client app connects desktop and mobile devices to its VPN service, with a Rust daemon and platform-specific frontends. It suits users who want privacy-focused tunneling and controls across major platforms.

wireguard-tools: Configure WireGuard VPN Tunnels
WireGuard tools provide the userspace commands for configuring and managing WireGuard tunnels across several operating systems. Use them to control interfaces directly or bring them up with the optional wg-quick helper.

ascii-chat: Video Chat in Your Terminal
ascii-chat turns webcam video into colored terminal art for live, multi-person calls over a client-server network. It also supports audio, encryption, and media from files or URLs, but setup involves a substantial native dependency stack.

Anthropic-Cybersecurity-Skills: Give AI Agents Security Playbooks
A library of structured cybersecurity workflows for AI agents, covering 34 security domains and mapped to six industry frameworks. Use it to provide compatible agents with practical guidance for authorized security work.

agentic-ai-prompt-research: Study Coding Assistant Prompt Design
An independent research project reconstructing prompt patterns and coordination mechanisms used by agentic coding assistants. It is intended for AI builders, prompt engineers, and security researchers, not as a verbatim copy of any proprietary system.

supply-chain-monitor: Detect Suspicious PyPI and npm Releases
Supply Chain Monitor tracks releases among popular PyPI and npm packages, compares each new release with its predecessor, and asks an LLM to flag suspicious changes. It suits teams that can operate Cursor Agent CLI and want Slack alerts for potential compromise.

apm: Manage Dependencies for AI Agent Setups
APM manages AI-agent instructions, skills, prompts, plugins, and MCP servers through a project manifest and lockfile. It helps teams reproduce agent configurations across supported coding clients and apply installation security and policy controls.

clawless: Run AI Agents in a Browser Sandbox
ClawLess runs Claw AI agents in a browser-based Node.js environment powered by WebContainers, without a backend server. It combines an editor, terminal, policy controls, and audit logging for teams building or evaluating sandboxed agent workflows.

bazzite: A Fedora-Based Linux System for Gaming
Bazzite is an image-based Fedora Linux distribution for gaming and everyday computing on desktops, handhelds, and home theater PCs. It combines gaming-focused defaults with system updates and rollback support.

waymore: Find and Download Archived URLs
waymore collects historical URLs from web archives and threat-intelligence sources, and can download archived responses for further analysis. It is aimed at security researchers and bug bounty hunters who value broad coverage over speed.

exifcleaner: Remove Metadata from Images and Media Files
ExifCleaner is a cross-platform desktop app for removing metadata from supported images, media files, and PDFs. It suits people who want a visual, batch-oriented privacy workflow, with format-specific limits to consider before relying on complete removal.