
security-harness
Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

A list of awesome penetration testing tools and resources.

Vulnerability Assessment Scanner with Report Generation

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Easy setup of static analysis tools for Android and Java projects.

Web-based Source Code Vulnerability Scanner

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Static code analysis plugin for Android project. (Checkstyle, PMD)