
apiscope
An API hooking framework for intercepting and monitoring Windows applications

An API hooking framework for intercepting and monitoring Windows applications

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Provides PoC exploits and root-cause analysis for two GitLab GraphQL `@gl_introduced` directive vulnerabilities: unauthenticated method execution and…

Martian is a library for building custom HTTP/S proxies

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

⚡️ Multiple target ZAP Scanning

Collaborative application security testing between humans and agents via CLI and MCP

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

PyJFuzz - Python JSON Fuzzer

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

WEB SERVICE SECURITY ASSESSMENT TOOL


Automated testing suite with live traffic record and replay

The collaborative web app pentest suite

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.