
TProxer
A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

A Burp Extension designed to identify argument injection vulnerabilities.

Automated testing suite with live traffic record and replay

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Node.js SDK for capturing and replaying API calls made to/from your service

Ruby command-line interface to Burp Suite's REST API

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

A program for testing WAF functionality

Collaborative application security testing between humans and agents via CLI and MCP

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

HTTP Proxy Analysis for reverse engineering protocol communication

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

API Scraper Agent for Web API's

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.