
gori
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Automatic SQL injection and database takeover tool

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis


Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Collaborative application security testing between humans and agents via CLI and MCP

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.