
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A wrapper around grep, to help you grep for things

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

Automated testing suite with live traffic record and replay

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

Laravel debug mode - Remote Code Execution (RCE)

The code for personally reproducing the corresponding vulnerability

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Exploit for Jenkins serialization vulnerability - CVE-2016-0792