Open-source repositories gaining traction right now.
41 repositories
#security
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0

The authentication glue you need.

Star OpenCTI-Platform / opencti Open Cyber Threat Intelligence Platform

An evolving how-to guide for securing a Linux server.

Shannon Lite is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.

The official NGINX Open Source repository.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Sponsor Star martin-olivier / airgorah A WiFi security auditing software mainly based on aircrack-ng tools suite

Star thalesgroup-cert / Watcher Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.

Star gravitational / teleport The easiest, and most secure way to access and protect all of your infrastructure.

Star kata-containers / kata-containers Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/

Star projectdiscovery / nuclei-templates Community curated list of templates for the nuclei engine to find security vulnerabilities.

Sponsor Star GyulyVGC / sniffnet Comfortably monitor your Internet traffic 🕵️♂️

Star ViRb3 / wgcf 🚤 Cross-platform, unofficial CLI for Cloudflare Warp

Star kyverno / kyverno Cloud Native Policy Management

Star fleetdm / fleet Open device management

Star ikarus23 / MifareClassicTool An Android NFC app for reading, writing, analyzing, etc. MIFARE Classic RFID tags.

Your browser catches homograph attacks. Your terminal doesn't. Tirith guards the gate — intercepts suspicious URLs, ANSI injection, and pipe-to-shell attacks before they execute.

Security Scanner for Agent Skills

Security harness for AI agents — egress proxy with DLP scanning, SSRF protection, MCP response scanning, and workspace integrity monitoring

Open source CLI to check compliance of your GitLab CI/CD pipelines and repos

🌟 Open Source AI Agent Security Infrastructure — intercepts and blocks dangerous agent behaviors before they happen. Just one command! Join us to build safer Human-AI Symbiosis!

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native fingerprintx/naabu pipeline integration.

boostsecurityio/bagel

sora2 watermark remover

42 AI agents. 9-layer consensus. One prompt. | Multi-agent orchestrator with ONNX neural routing, semantic convergence, and cross-LLM validation. https://nothumanallowed.com

IP Security Analyzer: A pro-grade Cloudflare Worker for forensic intelligence. Detects VPNs, Proxies & Hosting IPs via heuristic ASN auditing. Includes Security Scoring, WebRTC Leak Test, ISP classification, and Geo-location. Built with a modern Bento UI and live terminal logs. Powerful, open-source and real-time network forensic tool.

Open-source firewall for AI agents. Policy engine that controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.

Complete security layer for OpenClaw - CLI Scanner + Live Dashboard. Secrets detection, config hardening, prompt injection scanning, MCP server auditing. Zero telemetry.

Run Telegram MTProto proxy with docker compose

Package safety checks for AI agents before install via MCP

HTML obfuscation library and CLI for Rust. Renders identically in browsers but is hard for humans to read.

the smallest paranoid ai assistant that actually works. 100% rust.

自动化Web备份文件扫描、监控系统。集成备份文件扫描、任务调度等功能,可以帮助安全研究人员自动化地发现和监控目标域名的备份文件。

Google Play Store compliance scanner for Android apps - detects policy violations before submission

Secure authentication plugin for Paper/Spigot 1.21.x.

Code execution sandbox for AI agents with safety controls
Paste a github.com URL. Submissions are reviewed before they are tracked.