
vulnerable-mcp-servers-lab
A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack

Web-based Source Code Vulnerability Scanner

AndroBugs Framework is an efficient Android vulnerability scanner that helps developers or hackers find potential security vulnerabilities in Android…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Plugin for JADX to integrate MCP server

Connect your favorite AI agents directly to Cheat Engine via MCP. Automate reverse engineering, pointer scanning, and memory analysis using natural…

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Automatic SSTI detection tool with interactive interface

AI red-team platform. Autonomous LLM agents run a penetration test end to end inside a Kali container and write the report. LangGraph plan/act…

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

Ghidra is a software reverse engineering (SRE) framework

UNIX-like reverse engineering framework and command-line toolset

Main repo for hosting release binaries

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Agent skill for Android APK reverse engineering: dex patching, unpacking, repacking, ad and paywall removal, native .so analysis, and runtime…

Fast Android APK decompiler front-end that queries compiled DEX artifacts directly, extracting classes and cross-references in milliseconds without…