Best AI Security Agents 2026
Published 2026-09-12 · Data from nerq.ai · Updated hourly
Security is a natural fit for AI agents — from automated penetration testing to real-time threat detection. We ranked all 1,468 security agents in the Nerq index by Trust Score. In security especially, trust and maintenance quality matter — a poorly maintained security tool is worse than none at all.
Top 5 — in detail
1. promptfoo/promptfoo — agent
Test and evaluate LLMs for security vulnerabilities.
Trust: 86.0/100 (A) · GitHub · 18,373 stars · full report
2. raptor — agent
Raptor is an autonomous security research framework for advanced security operations and research.
Trust: 79.6/100 (B) · GitHub · 1,095 stars · full report
3. mcp-scan — agent
Security scanner for AI agents, MCP servers, and agent skills to detect vulnerabilities and prompt injections.
Trust: 79.1/100 (B) · GitHub · 1,460 stars · full report
4. CursorTouch/Windows-MCP — MCP server
MCP Server for Computer Use in Windows
Trust: 78.4/100 (B) · GitHub · 4,390 stars · full report
5. GreyDGL/PentestGPT — agent
Automated Penetration Testing Agentic Framework Powered by Large Language Models
Trust: 78.1/100 (B) · GitHub · 11,700 stars · full report
Full ranking — top 15
| # | Name | Type | Score | Grade | Source | Stars |
|---|---|---|---|---|---|---|
| 1 | promptfoo/promptfoo | agent |
86.0 | A | GitHub | 18,373 |
| Test and evaluate LLMs for security vulnerabilities. | ||||||
| 2 | raptor | agent |
79.6 | B | GitHub | 1,095 |
| Raptor is an autonomous security research framework for advanced security operations and research. | ||||||
| 3 | mcp-scan | agent |
79.1 | B | GitHub | 1,460 |
| Security scanner for AI agents, MCP servers, and agent skills to detect vulnerabilities and prompt injections. | ||||||
| 4 | CursorTouch/Windows-MCP | MCP server |
78.4 | B | GitHub | 4,390 |
| MCP Server for Computer Use in Windows | ||||||
| 5 | GreyDGL/PentestGPT | agent |
78.1 | B | GitHub | 11,700 |
| Automated Penetration Testing Agentic Framework Powered by Large Language Models | ||||||
| 6 | cisco-ai-defense/mcp-scanner | agent |
77.9 | B | GitHub | 809 |
| Scan MCP servers for potential threats & security findings. | ||||||
| 7 | FunnyWolf/agentic-soc-platform | agent |
77.7 | B | GitHub | 579 |
| Agentic SOC Platform: A powerful, flexible, open-source, and agent-centric automated security operations platform | ||||||
| 8 | SWE-agent/SWE-agent | agent |
76.9 | B | GitHub | 18,516 |
| SWE-agent takes a GitHub issue and tries to automatically fix it, using your LM of choice. It can also be employed for offensive cybersecurity or competitive coding challenges. ... | ||||||
| 9 | samugit83/redamon | agent |
76.8 | B | GitHub | 1,060 |
| An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention. | ||||||
| 10 | clawsec | agent |
76.6 | B | GitHub | 542 |
| ClawSec provides security features for AI agents, including drift detection and automated audits. | ||||||
| 11 | santosomar/AI-agents-for-cybersecurity | agent |
74.8 | B | GitHub | 146 |
| This repository contains resources and materials for the "AI Agents and Retrieval Augmented Generation (RAG) for Cybersecurity Operations" and other courses by Omar Santos. | ||||||
| 12 | duriantaco/skylos | agent |
74.7 | B | GitHub | 360 |
| High-precision Python SAST & Dead Code Remover. Finds unused functions, secrets, and security flaws with hybrid static analysis + local LLM agents. Privacy-first & low n... | ||||||
| 13 | cyproxio/mcp-for-security | MCP server |
74.5 | B | GitHub | 553 |
| MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. Integrate security testing and penetration... | ||||||
| 14 | SHAdd0WTAka/Zen-Ai-Pentest | tool |
74.3 | B | GitHub | 272 |
| AI-Powered Penetration Testing Framework | ||||||
| 15 | slither-mcp | MCP server |
73.8 | B | GitHub | 71 |
| MCP server for analyzing Solidity smart contracts. | ||||||
How we rank
Rankings are based on the Nerq Trust Score (0-100), a composite metric covering:
- Security (30%) — vulnerability audit, dependency safety
- Maintenance (25%) — commit recency, release cadence
- Popularity (20%) — stars, downloads, community
- Documentation (15%) — README, API docs, examples
- Ecosystem (10%) — protocol support, integrations
Scores update continuously as new data is crawled. These rankings reflect live data from the Nerq index of 1,468 security agents.
Related reports
- State of AI Assets — Q1 2026
- Best AI Coding Agents 2026
- Best AI Customer Service & Communication Agents 2026
- Best AI DevOps Agents 2026
- Best AI Content Creation Agents 2026