
pentest-ai
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Web vulnerability scanner written in Python3

Interactive web server for inspecting HTTP requests and forging responses, with a terminal UI for real-time debugging and API testing.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Automated HTTP Request Repeating With Burp Suite

PyJFuzz - Python JSON Fuzzer


Open-source adversary emulation for AI agents and MCP servers.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

SAML2 Burp Extension

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

A rapid HTTP downgrade smuggling scanner written in Go.

Damn Vulnerable C# Application (API)

⚡️ Multiple target ZAP Scanning

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Build structure-aware black-box HTTP fuzzers in Rust with composable mutators, schedulers, observers, deciders, and processors for custom web and API…