
shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Automated testing suite with live traffic record and replay

MCP server for Slither static analysis of Solidity smart contracts

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Executable security regression testing for agentic applications and MCP-integrated systems.

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.