Open-source repositories gaining traction right now.
24 repositories
#security
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

Sponsor Star GyulyVGC / sniffnet Comfortably monitor your Internet traffic 🕵️♂️

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0

The authentication glue you need.

SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!

Star projectdiscovery / nuclei-templates Community curated list of templates for the nuclei engine to find security vulnerabilities.

Star OpenCTI-Platform / opencti Open Cyber Threat Intelligence Platform

Star fleetdm / fleet Open device management

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

Your browser catches homograph attacks. Your terminal doesn't. Tirith guards the gate — intercepts suspicious URLs, ANSI injection, and pipe-to-shell attacks before they execute.

Security Scanner for Agent Skills

Star thalesgroup-cert / Watcher Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.

Sponsor Star martin-olivier / airgorah A WiFi security auditing software mainly based on aircrack-ng tools suite

Security harness for AI agents — egress proxy with DLP scanning, SSRF protection, MCP response scanning, and workspace integrity monitoring

🌟 Open Source AI Agent Security Infrastructure — intercepts and blocks dangerous agent behaviors before they happen. Just one command! Join us to build safer Human-AI Symbiosis!

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native fingerprintx/naabu pipeline integration.

boostsecurityio/bagel

IP Security Analyzer: A pro-grade Cloudflare Worker for forensic intelligence. Detects VPNs, Proxies & Hosting IPs via heuristic ASN auditing. Includes Security Scoring, WebRTC Leak Test, ISP classification, and Geo-location. Built with a modern Bento UI and live terminal logs. Powerful, open-source and real-time network forensic tool.

Open-source firewall for AI agents. Policy engine that controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.

Complete security layer for OpenClaw - CLI Scanner + Live Dashboard. Secrets detection, config hardening, prompt injection scanning, MCP server auditing. Zero telemetry.

自动化Web备份文件扫描、监控系统。集成备份文件扫描、任务调度等功能,可以帮助安全研究人员自动化地发现和监控目标域名的备份文件。

Secure authentication plugin for Paper/Spigot 1.21.x.
Paste a github.com URL. Submissions are reviewed before they are tracked.