
ftw
Framework for Testing WAFs (FTW!)

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Scalable fuzzing infrastructure with coverage-guided engines (libFuzzer, AFL, Honggfuzz), automated crash deduplication, bug filing, and regression…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Security Scanner for Agent Skills

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

LLM powered fuzzing via OSS-Fuzz.

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Easily create full virtual machines that are sandboxed for development or computer use models.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

RIPS - A static source code analyser for vulnerabilities in PHP scripts

👮 👊 RegEx Denial of Service (ReDos) Scanner

Model Context Protocol server for autonomous vulnerability discovery

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.