
OpenHunterAI
Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

CVE-2026-9830 Proof of Concept

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

A Burp Extension designed to identify argument injection vulnerabilities.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

The collaborative web app pentest suite

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Collaborative application security testing between humans and agents via CLI and MCP

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…