Open-source repositories gaining traction right now.
14 repositories
#security-tools
Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Sponsor Star qeeqbox / social-analyzer API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

Security harness for AI agents — egress proxy with DLP scanning, SSRF protection, MCP response scanning, and workspace integrity monitoring

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native fingerprintx/naabu pipeline integration.

IP Security Analyzer: A pro-grade Cloudflare Worker for forensic intelligence. Detects VPNs, Proxies & Hosting IPs via heuristic ASN auditing. Includes Security Scoring, WebRTC Leak Test, ISP classification, and Geo-location. Built with a modern Bento UI and live terminal logs. Powerful, open-source and real-time network forensic tool.

SecureE2E - Secret line for Secret chats with a VPS

Package safety checks for AI agents before install via MCP

自动化Web备份文件扫描、监控系统。集成备份文件扫描、任务调度等功能,可以帮助安全研究人员自动化地发现和监控目标域名的备份文件。
Paste a github.com URL. Submissions are reviewed before they are tracked.