Stars
Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.
Interactive roadmaps, guides and other educational content to help developers grow in their careers.
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise ide…
Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting
A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities
The official repository of Mozilla's Firefox web browser.
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works w…
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
pentestMCP: AI-Powered Penetration Testing via MCP, an MCP designed for penetration testers.
VSS Hardware Hacking Wiki and Blog Entries
This repository is a carefully chosen collection of cloud security-related interview questions and scenarios. This resource will help you explore different areas of safeguarding cloud systems, whet…
Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable SSRF candidates.
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Explanation and full RCE PoC for CVE-2025-55182
🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.
A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features common vulnerabilities found in real-wor…
Digital fraud affects so many organizations. In this demo, you'll learn the components of a real-time fraud detection system, and how to build one with Tinybird.
Damn Vulnerable Web Services is a vulnerable application with a web service and an API that can be used to learn about webservices/API related vulnerabilities.
Subdosec is a fast, accurate subdomain takeover scanner with no false positives. It also offers a database of sites vulnerable to subdomain takeover (public results), along with detailed metadata l…