SecGPT — security grade SAFE, quality 70/100

Security audit verdict: SAFE · quality 70/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by ZacharyZcR · LLM Plugin · ★ 286

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is SecGPT safe to install? View the security audit →

About SecGPT

SecGPT SecGPT is an open-source project inspired by AutoGPT, borrowing from its prompts and design patterns, but with significant code refactoring. As a solo developer project, we cannot guarantee the full quality of the code, but it has been extensively optimized and refactored in conjunction with GPT-4. We hope this will improve the overall code quality to some extent. Inheriting the philosophy of AutoGPT, the uniqueness of SecGPT lies in its more refined plugin functionality. SecGPT aims to make further contributions to network security by combining LLM, including penetration testing, red-blue confrontations, CTF competitions, and other aspects. How does SecGPT work? It aggregates existing plugin features and makes decisions through AI. Based on these decisions, it constructs basic behavior logic. Then, following this logic, it calls local plugin functions to attempt tasks such as website penetration, vulnerability scanning, code audit, and report writing. The update speed is slow, the author is reading and learning the source code of LangChain. The plugin is being written and tested, if you are interested, you can join our development. ![Static Badge](https://img.shields.io/ba

aiautogptcybersecuritylangchainllmsecgptsecurity

Quick Facts

Stars286
Forks75
LanguagePython
CategoryLLM Plugin
LicenseApache-2.0
Quality Score70.435413019087/100
Last Updated2023-11-15
Created2023-06-27
Platformspython
Est. Tokens~13k

SecGPT alternative? Top 6 similar tools

Looking for a SecGPT alternative? If you're comparing SecGPT with other llm plugin tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • sre by SmythOS · ⭐ 1.3k

    The SmythOS Runtime Environment (SRE) is an open-source, cloud-native runtime for agentic AI. Secure, modular,

  • Wazuh-MCP-Server by gensecaihq · ⭐ 232

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • allama by digitranslab · ⭐ 197

    🔥🔥🔥 AI security automation platform. Build visual workflows, deploy autonomous agents, and automate threat

  • Awesome-AI-For-Security by AmanPriyanshu · ⭐ 145

    A curated list of tools, papers, and datasets for applying AI to cybersecurity tasks. This list primarily focu

  • flock by Onelevenvy · ⭐ 1.1k

    Flock is a workflow-based low-code platform for rapidly building chatbots, RAG, and coordinating multi-agent t

  • agentic-radar by splx-ai · ⭐ 1.1k

    A security scanner for your LLM agentic workflows

More LLM Plugin Tools

Explore other popular llm plugin tools:

View all LLM Plugin tools →

Popular Python Agent Tools

Frequently Asked Questions

What is SecGPT?

SecGPT is A Test Project for a Network Security-oriented LLM Tool Emulating AutoGPT. It is categorized as a LLM Plugin with 286 GitHub stars.

What programming language is SecGPT written in?

SecGPT is primarily written in Python. It covers topics such as ai, autogpt, cybersecurity.

How do I install or use SecGPT?

You can find installation instructions and usage details in the SecGPT GitHub repository at github.com/ZacharyZcR/SecGPT. The project has 286 stars and 75 forks, indicating an active community.

What license does SecGPT use?

SecGPT is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to SecGPT?

The top alternatives to SecGPT on Agent Skills Hub include sre, Wazuh-MCP-Server, allama. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse LLM Plugin tools