{
  "$schema_doc": "https://gtmstacker.com/registry/schema/entry.schema.json",
  "stability": "emerging",
  "generator": "agentic-media-registry",
  "generated_at": "2026-09-10T00:00:00Z",
  "id": "com.gtmstacker.registry/tool/security-cards",
  "type": "tool",
  "slug": "security-cards",
  "canonical_url": "https://gtmstacker.com/registry/tool/security-cards/",
  "title": "Security Cards",
  "description": "Open-source security-guidance dataset and installable agent skill (Astro site + data): targeted, version-aware security best practices for 80+ widely-used libraries across 13 languages, aimed at coding agents that write functionally-correct-but-insecure code. In the makers' BaxBench eval, wiring it into Claude Code (Opus 4.7) cut the insecure-code rate from 23.9% to 6.6%.",
  "category": "mcp-agents",
  "tags": [
    "mcp-agents",
    "agent-security",
    "claude-skills",
    "secure-coding",
    "governance",
    "dataset"
  ],
  "status": "active",
  "revision": 1,
  "content_hash": "01a0da92e896b14d2e3063982a0f8eae42a96f932f6648b25d7c0614bec57acb",
  "date_published": "2026-09-10T00:00:00Z",
  "date_modified": "2026-09-10T00:00:00Z",
  "source": {
    "name": "github · Reware-Labs/securitycards",
    "url": "https://github.com/Reware-Labs/securitycards"
  },
  "license": "Apache-2.0",
  "one_liner": "Security Cards is an open-source security-guidance dataset + agent skill for 80+ libraries, to stop coding agents writing insecure code.",
  "open_source": "yes",
  "self_hostable": "yes",
  "pricing_model": "free",
  "who_its_for": "Teams whose coding agents ship insecure code and want library-specific security guidance injected as a skill.",
  "aliases": [
    "Security Cards",
    "securitycards"
  ],
  "alternatives": [
    "stroq",
    "tripwire-agent-scanner"
  ],
  "secondary_categories": [
    "ai-infrastructure"
  ],
  "last_verified": "2026-09-10",
  "evidence": {
    "claim_type": "mixed",
    "source_id": "https://github.com/Reware-Labs/securitycards",
    "note": "License + traction WebFetch-verified 2026-09-10; feature claims are vendor/README."
  },
  "caveats": "The '72.3% relative reduction' (23.9%→6.6%) is the makers' own BaxBench result (216 tasks, Claude Code + Opus 4.7) — a vendor benchmark, not independently reproduced here. It is guidance/data + a skill, not a runtime-enforcement tool.",
  "lead": "Open-source security-guidance dataset and installable agent skill (Astro site + data): targeted, version-aware security best practices for 80+ widely-used libraries across 13 languages, aimed at coding agents that write functionally-correct-but-insecure code. In the makers' BaxBench eval, wiring it into Claude Code (Opus 4.7) cut the insecure-code rate from 23.9% to 6.6%.",
  "chunks": [
    {
      "index": 0,
      "heading_path": [],
      "est_tokens": 94,
      "text": "Open-source security-guidance dataset and installable agent skill (Astro site + data): targeted, version-aware security best practices for 80+ widely-used libraries across 13 languages, aimed at coding agents that write functionally-correct-but-insecure code. In the makers' BaxBench eval, wiring it into Claude Code (Opus 4.7) cut the insecure-code rate from 23.9% to 6.6%."
    },
    {
      "index": 1,
      "heading_path": [
        null,
        "Provenance"
      ],
      "est_tokens": 198,
      "text": "security-guidance dataset and installable agent skill (Astro site + data): targeted, version-aware security best practices for 80+ widely-used libraries across 13 languages, aimed at coding agents that write functionally-correct-but-insecure code. In the makers' BaxBench eval, wiring it into Claude Code (Opus 4.7) cut the insecure-code rate from 23.9% to 6.6%.\n\n- Apache-2.0 independently WebFetch-verified 2026-09-10 (18★, 25 commits; repo Reware-Labs/securitycards, Astro + data/skills). Surfaced via the 2026-09-10 daily pull as the strongest individual anchor of the agent-safety cluster. The 72% figure is vendor-claimed (BaxBench).\n- Curated from the GTM Stacker signal registry (2026-09-10 pass: daily pull + viral-posts brief); license independently WebFetch-verified 2026-09-10."
    }
  ],
  "alternates": {
    "markdown": "https://gtmstacker.com/registry/tool/security-cards/index.md",
    "html": "https://gtmstacker.com/registry/tool/security-cards/",
    "json": "https://gtmstacker.com/registry/tool/security-cards/index.json",
    "server_json": "https://gtmstacker.com/registry/tool/security-cards/server.json"
  },
  "jsonld": {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "WebSite",
        "@id": "https://gtmstacker.com/#website",
        "url": "https://gtmstacker.com/",
        "name": "GTM Stacker Agent Registry",
        "description": "A daily-updated, agent-native registry of open-source tool discoveries, tool updates, and curated news for the go-to-market / RevOps engineering niche. Machine-readable first: agents can discover, parse, page, and delta-sync it without scraping HTML.",
        "inLanguage": "en",
        "publisher": {
          "@id": "https://gtmstacker.com/#organization"
        }
      },
      {
        "@type": "Organization",
        "@id": "https://gtmstacker.com/#organization",
        "name": "GTM Stacker",
        "url": "https://gtmstacker.com",
        "description": "The growth-systems practice of Theo Popov: AI-native enrichment, outbound, content engines and internal tooling for startups and venture programs. Its agent-native media property, the GTM Stacker Agent Registry, maintains a daily-updated catalog of open-source go-to-market and RevOps tools that both people and AI engines can discover, compare, and cite.",
        "foundingDate": "2024-08",
        "knowsAbout": [
          "go-to-market engineering",
          "RevOps",
          "sales automation",
          "marketing operations",
          "open-source software",
          "AI agents"
        ],
        "founder": {
          "@type": "Person",
          "@id": "https://gtmstacker.com/#founder",
          "name": "Theo Popov",
          "jobTitle": "Growth Operations & GTM Systems",
          "url": "https://gtmstacker.com/about/",
          "sameAs": [
            "https://www.linkedin.com/in/theo-popov",
            "https://x.com/Theo_Popov",
            "https://github.com/theopopov"
          ],
          "worksFor": {
            "@id": "https://gtmstacker.com/#organization"
          }
        },
        "mainEntityOfPage": "https://gtmstacker.com/registry/about/"
      },
      {
        "@type": "SoftwareApplication",
        "@id": "https://gtmstacker.com/registry/tool/security-cards/#software",
        "name": "Security Cards",
        "identifier": "io.github.reware-labs/securitycards",
        "description": "Open-source security-guidance dataset and installable agent skill (Astro site + data): targeted, version-aware security best practices for 80+ widely-used libraries across 13 languages, aimed at coding agents that write functionally-correct-but-insecure code. In the makers' BaxBench eval, wiring it into Claude Code (Opus 4.7) cut the insecure-code rate from 23.9% to 6.6%.",
        "applicationCategory": "DeveloperApplication",
        "url": "https://gtmstacker.com/registry/tool/security-cards/",
        "datePublished": "2026-09-10T00:00:00Z",
        "dateModified": "2026-09-10T00:00:00Z",
        "isPartOf": {
          "@id": "https://gtmstacker.com/#website"
        },
        "license": "Apache-2.0",
        "codeRepository": "https://github.com/Reware-Labs/securitycards",
        "keywords": "mcp-agents, ai-infrastructure, agent-security, claude-skills, secure-coding, governance, dataset",
        "author": {
          "@type": "Organization",
          "name": "Reware-Labs",
          "url": "https://github.com/Reware-Labs",
          "sameAs": [
            "https://github.com/Reware-Labs/securitycards"
          ]
        },
        "offers": {
          "@type": "Offer",
          "price": 0,
          "priceCurrency": "USD"
        },
        "isSimilarTo": [
          {
            "@type": "SoftwareApplication",
            "name": "Stroq",
            "url": "https://gtmstacker.com/registry/tool/stroq/"
          },
          {
            "@type": "SoftwareApplication",
            "name": "Tripwire",
            "url": "https://gtmstacker.com/registry/tool/tripwire-agent-scanner/"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "@id": "https://gtmstacker.com/registry/tool/security-cards/#breadcrumb",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "GTM Stacker Registry",
            "item": "https://gtmstacker.com/registry/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "MCP Agents",
            "item": "https://gtmstacker.com/registry/category/mcp-agents/"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Security Cards",
            "item": "https://gtmstacker.com/registry/tool/security-cards/"
          }
        ]
      }
    ]
  },
  "tool": {
    "name": "io.github.reware-labs/securitycards",
    "repository": {
      "url": "https://github.com/Reware-Labs/securitycards",
      "source": "github"
    }
  }
}
