
shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

A wrapper around grep, to help you grep for things

Build and query a graph database representation of source code

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Automated testing suite with live traffic record and replay

MCP server for Slither static analysis of Solidity smart contracts

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Executable security regression testing for agentic applications and MCP-integrated systems.

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Fuzzing Framework for Modules in Apache HTTPD Server

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs