
sast-scan-action
GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Rust-powered HTTP Request Smuggling Scanner.

CLI tool for the Horizon3.ai API

AI-powered offensive security testing using autonomous agents, directly in your terminal.


Vulnerability Assessment Scanner with Report Generation

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Executable security regression testing for agentic applications and MCP-integrated systems.

Burp Extension for collaboration in Faraday

Faraday's Command Line Interface