English | 简体中文 | Español
Introduction
Scanners Box is a curated arsenal of 9,000+ ⭐ open-source cybersecurity treasures — with a special focus on AI-driven automated security agents and Red Team / Blue Team tooling. All tools feature source code available, covering 10+ categories from subdomain enumeration to IoT auditing, mobile analysis, smart contract scanning, and cloud security.
Project A³C
A³C — Autonomous AI Certification

Projects displaying the A³C badge are officially certified by Scanners Box as trusted, active AI-powered autonomous projects.
The A³C badge is Scanners Box's official certification for open-source AI-powered autonomous projects — verified, active, and trusted tools powered by artificial intelligence.

Contents
[!IMPORTANT]
❋⚛🐋 For AI
AI Autonomous Cybersecurity Agents
- https://github.com/oritera/Cairn - A general-purpose state-space search engine validated on autonomous penetration testing — no predefined roles or workflows, purely goal-driven pathfinding

- https://github.com/KeygraphHQ/shannon - Autonomous white-box AI pentester for web apps & APIs — analyzes source code, identifies attack vectors, and executes real exploits pre-production


- https://github.com/SanMuzZzZz/LuaN1aoAgent - LuaN1ao (鸾鸟) - A next-generation Autonomous Penetration Testing Agent powered by LLMs, integrating P-E-R Agent Collaboration with Causal Graph Reasoning to simulate security expert thinking patterns

- https://github.com/Ed1s0nZ/CyberStrikeAI - An AI-native security testing platform in Go, integrating 100+ tools, intelligent orchestration, role-based testing, skills system, full lifecycle management, and a built-in lightweight C2 framework for authorized engagements

- https://github.com/ASCIT31/Dark-Moon - Autonomous AI pentesting engine performing continuous offensive security across web, cloud, AD and Kubernetes. Uses agentic reasoning, real exploit execution and attack path analysis to deliver proof-based vulnerabilities.

LLM-Powered Vulnerability Scanners

- https://github.com/vercel-labs/deepsec - An agent-powered vulnerability scanner for on-demand review of all code in existing large-scale repos, surfacing hard-to-find issues that have been lurking in applications for a long time


Security Auditing for AI Apps
- https://github.com/leondz/garak - LLM vulnerability scanner for hallucination, data leakage, promp injection, misinformation, toxicity generation, jailbreaks, and many other weaknesses




AI Agent Runtime Controls
- https://github.com/agentkitai/agentgate - Approval workflow engine for AI agents — define policies to auto-approve safe actions, auto-deny dangerous ones, and route the rest to a human via dashboard, Slack, Discord, or email

Security Auditing for Agent Skills
- https://github.com/NVIDIA/SkillSpector - Security scanner for AI agent skills — detect vulnerabilities, malicious patterns, and security risks before installing agent skills (Claude Code, Codex CLI, Gemini CLI, etc.)

- https://github.com/cisco-ai-defense/skill-scanner - A best-effort security scanner for AI Agent Skills — detects prompt injection, data exfiltration, and malicious code patterns via pattern-based detection (YAML+YARA), LLM-as-a-judge, and behavioral dataflow analysis. Supports OpenAI Codex Skills, Cursor Agent Skills, and Claude Code commands.



Scanners for Smart Contracts





Red Team vs Blue Team
Supply Chain Analysis(SCA)

Container and Cluster









Services fingerprint detection


Man-In-The-Middle

The framework











Wireless Pentest







Mobile Apps Packages Analysis









Binary Executables Analysis





Privacy Compliance


Subdomain Enumeration or Takeover





































Database SQL Injection Vulnerability or Brute Force
















Weak Usernames or Passwords Enumeration For Web






IoT Hardware Automated Audit








- https://github.com/bahaabdelwahed/st - An advanced security tool engineered specifically to scrutinize and detect threats within the intricate protocols utilized by IoT (Internet of Things) devices



Mutiple types of Cross-site scripting Detection





- https://github.com/stamparm/DSXS - A fully functional cross-site scripting vulnerability scanner,supporting GET and POST parameters,and written in under 100 lines of code





















Malware Detection





Vulnerability Assessment for Middleware








Read more