Lists (10)
Sort Name ascending (A-Z)
Stars
Scan your project for suspicious or malicious dependencies
Agentic AI security tool that applies proactive, attacker-first analysis directly to source code.
Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.
Self-hosted external attack surface scanner. Subdomain enumeration + takeover detection, ports, CVEs, TLS, SSH, web vulns, EPSS/KEV prioritisation. 19 tools across 6 phases, one `docker run`. MIT-l…
A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists, and a local VM practice lab.…
A comprehensive guide to adversarial testing and security evaluation of AI systems, helping organizations identify vulnerabilities before attackers exploit them.
Instant, Concurrent, Secure & Lightweight Sandbox for AI Agents.
A simple utility to generate domain names with all possible TLDs
The agent that grows with you
Pure python3 implementation for working with iDevices (iPhone, etc...).
Security testing tool for exposed Ollama API endpoints, CVE vulnerabilities and advanced probes
The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers across function-level, repository-level, agentic, a…
How To approach recon on real targets — from passive enumeration to origin IP discovery. Covers tools, automation, and the logic behind each phase.
Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents
A fast tool to scan CRLF vulnerability written in Go
Anyone who has used Burp Suite Repeater for more than 20 minutes knows the problem. You send request after request, and every tab is named 1, 2, 3... Ten tabs in, you are clicking through each one …
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if hand…
Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code…
Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery
Offensive knowledge, offline. One search box for every playbook.
Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.