
shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Exploit tool for CVE-2024-36104 targeting Apache OFBiz code execution vulnerability. Supports single and batch URL scanning with proxy and threading…

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

The code for personally reproducing the corresponding vulnerability

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

A wrapper around grep, to help you grep for things

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Executable security regression testing for agentic applications and MCP-integrated systems.

Fuzzing Framework for Modules in Apache HTTPD Server

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.