
mzap
⚡️ Multiple target ZAP Scanning

⚡️ Multiple target ZAP Scanning

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automated testing suite with live traffic record and replay

An API hooking framework for intercepting and monitoring Windows applications

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Hermes Proxy - HTTP Traffic Analyzer

Martian is a library for building custom HTTP/S proxies

WEB SERVICE SECURITY ASSESSMENT TOOL

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…