
HybridTestFramework
End to End testing of Web, API, Cloud, Events and Security

End to End testing of Web, API, Cloud, Events and Security

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Executable security regression testing for agentic applications and MCP-integrated systems.

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Burp Extension for collaboration in Faraday

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

OPNsense GUI, API and systems backend

Rust-powered HTTP Request Smuggling Scanner.

⚡️ Multiple target ZAP Scanning

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

nginx 1.15.10 patch against cve-2021-23017 (ingress version)

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.