
xalgorix
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

Modular Android APK security analysis framework integrating static, dynamic, and reverse engineering tools for comprehensive vulnerability assessment…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

REx@Skill - Agentic Reverse Engineering eXecution Skill for binary vulnerability discovery

Controlled vulnerability research and reproduction lab for CVE-2020-14343 in PyYAML

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Containerized educational CTF lab emulating CVE-2026-80428 (CWE-502 deserialization) for safe, isolated student and researcher practice.

Non-decompiling iOS/Android app vulnerability scanner (DC25 demo lab, CB17)

Model Context Protocol server for autonomous vulnerability discovery

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Analysis Plugin and Tools for Vivisect

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)