
reburp
A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

Executable security regression testing for agentic applications and MCP-integrated systems.

MCP server for Slither static analysis of Solidity smart contracts

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

The collaborative web app pentest suite

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks