
smugglex
Rust-powered HTTP Request Smuggling Scanner.

Rust-powered HTTP Request Smuggling Scanner.

Vulnerability Assessment Scanner with Report Generation

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Executable security regression testing for agentic applications and MCP-integrated systems.

Burp Extension for collaboration in Faraday

MCP server for Slither static analysis of Solidity smart contracts


50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Automated testing suite with live traffic record and replay

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.