
vulnhawk
AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

MCP server for Slither static analysis of Solidity smart contracts

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

CLI component of purpleteam

Application scanning component of purpleteam

Server scanning component of purpleteam