
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Generates SCAP, Ansible, Bash, and CEL security content for compliance evaluation and automated hardening across Linux hosts, containers, and…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

⚡️ Multiple target ZAP Scanning

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Rust-powered HTTP Request Smuggling Scanner.

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

Executable security regression testing for agentic applications and MCP-integrated systems.

Vulnerability Assessment Scanner with Report Generation

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)
