
nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Main repo for hosting release binaries

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

AI-Powered Reverse Engineering Plugin for IDA Pro

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Claude Code skill for reverse-engineering 32-bit little-endian x86 C++ binaries (vtables, RTTI, inheritance recovery)

PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

Static analysis of malicious Python code