
libretto
The AI toolkit for building reliable browser automations

The AI toolkit for building reliable browser automations

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Collaborative application security testing between humans and agents via CLI and MCP

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Hermes Proxy - HTTP Traffic Analyzer

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

⚡️ Multiple target ZAP Scanning

The collaborative web app pentest suite

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

An API hooking framework for intercepting and monitoring Windows applications

Automated testing suite with live traffic record and replay