
mariana-trench
A security focused static analysis tool for Android and Java applications.

A security focused static analysis tool for Android and Java applications.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision


Main repo for hosting release binaries

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

An easy-to-learn/use static analysis framework for Java and Android

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Plugin for JADX to integrate MCP server

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…


Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

Executable security regression testing for agentic applications and MCP-integrated systems.

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

Reproducer for CVE-2026-46455 — Apache Camel camel-keycloak missing TokenVerifier.IS_ACTIVE check (expired access tokens accepted)