No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by FrancescoStabile · MCP Server · ★ 466
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is numasec safe to install? View the security audit →
numasec The open source AI security agent. Give your terminal a security brain. Run security workflows with your local tools, agents, runbooks, findings, evidence, replay and reports. npm install -g numasec <img src="https://img.shields.io/github/stars/FrancescoStabile/numasec.svg?style=for-the-badge&label=stars&logo=github&logoColor=white&labelColor=0b0f0a&color=f5a524&cacheSeconds=1800" alt="Gi
| Stars | 466 |
| Forks | 51 |
| Language | TypeScript |
| Category | MCP Server |
| License | AGPL-3.0 |
| Quality Score | 61.1954907678988/100 |
| Open Issues | 4 |
| Last Updated | 2026-05-08 |
| Created | 2026-02-02 |
| Platforms | browser, cli, mcp, node |
| Est. Tokens | ~17967k |
These tools work well together with numasec for enhanced workflows:
Looking for a numasec alternative? If you're comparing numasec with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Open-source adversary emulation for AI agents and MCP servers.
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply cha
An AI red-team agent for authorized labs and web app pentesting workflows. Turns Claude Code / OpenCode / Code
Explore other popular mcp server tools:
numasec is The AI Agent for Cyber Security.. It is categorized as a MCP Server with 466 GitHub stars.
numasec is primarily written in TypeScript. It covers topics such as ai-agent, ai-security, appsec.
You can find installation instructions and usage details in the numasec GitHub repository at github.com/FrancescoStabile/numasec. The project has 466 stars and 51 forks, indicating an active community.
numasec is released under the AGPL-3.0 license, making it free to use and modify according to the license terms.
The top alternatives to numasec on Agent Skills Hub include CyberStrike, pentest-ai, pentest-ai-agents. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: