
pwnproxy
An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

Generates SCAP, Ansible, Bash, and CEL security content for compliance evaluation and automated hardening across Linux hosts, containers, and…

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

Rust-powered HTTP Request Smuggling Scanner.

Vulnerability Assessment Scanner with Report Generation

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)


Executable security regression testing for agentic applications and MCP-integrated systems.

Burp Extension for collaboration in Faraday

MCP server for Slither static analysis of Solidity smart contracts

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…