Search
Awesome Pentest Tools
kOaDT
Open-source offensive security tools, plus a vendor-agnostic AI agent that runs authorized pentest engagements using only tools from this list.
...moreasfops
Agentic Security Fleet Ops — an LLM-agent security department with a Security Orchestrator, built on pydantic-ai with a GitHub Copilot SDK provider.
...morereact-native-malwarelytics
kober
Malwarelytics for React Native protects your banking or fintech app from a broad range of mobile security threats with an industry-leading mobile threat intelligence solution.
...morenode-api-guard
developer.wk
Node-API-Guard is a lightweight middleware for securing Node.js APIs with features like rate limiting, IP blocking, CORS control, and logging.
...more@shomra/agent
shomra-ai
Shomra — a local-first security scanner and runtime firewall for AI agents, MCP servers, prompts, and models. Gates AI artifacts in your editor and CI.
...moretaintmcp
khs28
A runtime, client-side security gateway for the Model Context Protocol (MCP). Blocks indirect prompt injection, tool poisoning, rug-pulls, and tool shadowing.
...morensauditor-ai-agent-skill
nsasoftus
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows.
...morePhantom
ghostwright
An AI co-worker with its own computer. Self-evolving, persistent memory, MCP server, secure credential collection, email identity. Built on the Claude Agent SDK.
...moreautoai-agentshield
autoailabsuk
The security gateway for AI agent communication protocols (MCP, A2A). Prompt injection detection, audit logging, rate limiting, trust scoring, and policy enforcement.
...morerandom-password-toolkit
krishnatadi
A powerful and versatile tool for generating secure, customizable passwords with encryption, decryption, and password strength validation features, random number, api key generator, otp generator.
...moreRedhound Arsenal
redhoundinfosec
76 AI-agent security skills for Kali Linux tools — pentest, red team, forensics, OSINT, and more. Machine-readable skill definitions by Red Hound InfoSec.
...morellm-bouncer
llm-bouncer
Detect and block LLM security threats — prompt injection, PII, secrets, and unsafe output — in Node.js & TypeScript. One-line Next.js integration, zero dependencies.
...moreupstream-radar
GitHub Actions
Always-on dependency security monitoring for DeepSeek Harness (DSH) plugins: find exact installed or candidate transitive vulnerable paths and breaking updates, then route evidence to a DSH Agent.
...moreCyber Agent
nickyjacobs
AI-powered cybersecurity agent for Kali Linux that autonomously orchestrates security tools, analyzes output and maps findings to MITRE ATT&CK using Claude Agent SDK.
...moreLog4ShellAuditor
C00LN3T
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell).
...moremore-to-store
meezan35
`More to Store` is a lightweight and fast utility to interact with `localStorage`, providing optional encryption, automatic expiration, and seamless data management. Perfect for modern web applications that require secure, persistent, and optimized storag
...more@eternaljs/otp-generator
gchandrasekhar
An OTP (One-Time Password) generator is a crucial tool for enhancing security in digital transactions and logins. It generates unique, time-sensitive codes that serve as an additional layer of authentication. This adds an extra level of protection against
...morepaymcp-security
sksamimgoodboy
PayMCP — an MCP server that helps AI coding agents add, audit, test, and debug payment integrations (V0.1: Razorpay + Next.js). Step 1: MCP foundation + secure read-only workspace layer.
...moreCross Code Organizer
mcpware
Cross-Code Organizer (formerly Claude Code Organizer): cross-harness config dashboard for Claude Code, Codex CLI, MCP servers, skills, memories, agents, sessions, security scanning, context budget, and backups.
...moreMcpVanguard
provnai
An open-source security proxy and active firewall for the Model Context Protocol (MCP). It acts as a real-time 'Reflex System' between AI agents and their tools, protecting the host system from malicious intent, prompt injection, and data exfiltration.
...more