
toolbox
Collaborative application security testing between humans and agents via CLI and MCP

Collaborative application security testing between humans and agents via CLI and MCP

A Frida UI tool window inside PyCharm / JetBrains IDEs.

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…

Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)

HTTP Proxy Analysis for reverse engineering protocol communication

基于asyncio(协程)的CVE-2020-0796 速度还是十分可观的,方便运维师傅们对内网做下快速检测。

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…


SleuthQL是基于python3所开发的一款,用于批量爬行站点可能存在sql的地址。并且可以配合burp+sqlmap进行批量注入。 对比sqlmap手动单线程一个一个注入点的去识别,方便了很多。

CVE-2021-22005批量验证python脚本

API Scraper Agent for Web API's

CVE-2019-0708批量检测

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Ansible playbook to test systems for the Dirty COW privilege escalation vulnerability (CVE-2016-5195) with automated local exploitation checks.

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

Alexa skill example for Faraday API

Basic BASH Script to Automate OpenSSL based testing for FREAK Attack (CVE-2015-0204) as advised by Akamai.