
security-harness
Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

PHP Static Analysis Tool - discover bugs in your code without running it!

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

A list of awesome penetration testing tools and resources.

Linting tool for CloudFormation templates

The Secure Coding Framework

Vulnerability Assessment Scanner with Report Generation

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Open-source, cross-platform, multi-purpose security auditing tool

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

UT based automated fuzz driver generation