
ship-safe
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Wire-level proxy firewall for AI agents that intercepts and gates SQL, Kubernetes, and HTTP traffic using HCL rules, with per-process tunnel…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

The AI toolkit for building reliable browser automations

Metlo is an open-source API security platform.

Tests your WAF with +160 payloads

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Open-source adversary emulation for AI agents and MCP servers.

The DevSecOps toolset for REST APIs

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

SSRF plugin for burp Automates SSRF Detection in all of the Request