Skip to content
85

Awesome AI Security Tools

A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven fuzzing, threat intelligence, SOC/SIEM triage, reverse engineering, LLM red-teaming, and more.

1.6k stars385 forks329 entriesLast push Sep 27, 2026 (2 days ago)License Other

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Autotriage of Security Findings

nuclei-autotriage

🟢⚠️ — Two-stage LLM triage (falsifier + red-team pass) of Nuclei JSONL findings via OpenAI-compatible endpoints (vLLM/Ollama). (CyberOK) — note: restrictive personal/non-commercial EULA, not a permissive OSS license. · updated 2026-05-25); Related: agent-audit · asamm

seclab-taskflow-agent

🟢 — YAML-driven taskflow agent framework for triaging CodeQL/SAST alerts and filtering false positives. (GitHub Security Lab) · updated 2026-08-17); Related: SigmaOptimizer

honeyslop

🟢 — Code-canary decoys to triage AI-hallucinated ("slop") vulnerability reports flooding bug-bounty programs. · updated 2026-05-20)

nano-analyzer

🟢🔬 — Minimal three-stage LLM pipeline (context → scan → skeptical triage) for zero-day discovery in C/C++. (AISLE) · updated 2026-04-14)

SigmaOptimizer

🟢 — Generates, tests, and refines Sigma rules from real logs with false-positive checking. · updated 2025-08-01); Related: soctalk · seclab-taskflow-agent

ai-soc-triage-assistant

🟢⚠️ — SOC alert triage assistant with prompt-injection guardrails, output validation, and MITRE ATT&CK mapping. · updated 2026-02-23)

AI Agent & Coding-Agent Security >Scanners & Auditors

agent-audit

🟢 — Forensic auditor for local AI coding agents (Claude Code, Codex CLI, OpenClaw) and project-surface scanner for repos shipping skills, plugins, and MCP manifests; 296 bundled rules across native + imported detector families, with optional LLM cross-verification. (CyberOK / S. Gordeychik) ·…;…

AI-Infra-Guard

🟢 — Full-stack AI red-teaming platform covering OpenClaw security scan, agent scan, skills scan, MCP scan, AI-infra vulnerability scan, and LLM jailbreak evaluation. (Tencent Zhuque Lab) · updated 2026-09-10); Related: agent-audit · aguara · Cisco AI Defense – skill-scanner · Cisco AI Defense –…

In 4 listsDetails

SkillSpector

🟢 — Security scanner for AI-agent skills used by Claude Code, Codex CLI, Gemini CLI, and similar ecosystems; combines static analysis, AST/YARA/taint checks, optional LLM semantic review, MCP least-privilege/tool-poisoning checks, risk scoring, and SARIF/JSON/Markdown output. (NVIDIA) · updated…;…

In 5 listsDetails

Ramparts

🟢 — Rust scanner for MCP servers and agent-skill bundles with YARA rules, optional LLM analysis, OSV/CVE lookups, OWASP MCP Top 10 mapping, and SARIF/JSON/Markdown reports. · updated 2026-08-07); Related: SkillSpector · Cisco AI Defense – skill-scanner · Cisco AI Defense – mcp-scanner

mcp-armor

🟢 — Local MCP security scanner with auto-discovery for agentic IDE configs, tool/resource/prompt inventory, prompt-injection checks, rug-pull and tool-poisoning detection, baseline drift monitoring, and JSON/Markdown reports. (Aira Security) · updated 2026-03-27); Related: SkillSpector · Ramparts…

aguara

🟢 — Single-binary static scanner (Go, no LLM) for AI-agent skills and MCP servers; multi-layer engine (pattern + NLP + taint tracking + rug-pull detection). Companion aguara-mcp exposes scanning as an MCP tool. · updated 2026-08-12); Related: aguara-mcp · agent-audit · Snyk Agent Scan · Cisco AI…

agent-scan

🟢 — Security scanner for AI agents, MCP servers, and agent skills; the successor path for the original Invariant Labs mcp-scan work. (Snyk) · updated 2026-08-13); Related: aguara · Cisco AI Defense – mcp-scanner · Cisco AI Defense – skill-scanner

In 3 lists

inkog

🟠 — Commercial-backed static security scanner for AI agents across LangChain, LangGraph, CrewAI, AutoGen, and no-code workflows; Apache-2.0 CLI with proprietary deep-scan engine. (Inkog) · updated 2026-06-07); Related: Snyk Agent Scan · agentic-radar

AgentShield

🟢 — Security scanner for AI-agent configurations, MCP servers, hooks, and tool permissions with CLI, GitHub Action, and app workflows. · updated 2026-07-22); Related: agent-audit · Snyk Agent Scan

In 2 lists

repo-forensics

🟢⚠️ — Offline scanner for AI-agent repos, skills, plugins, and MCP servers; license is PolyForm Noncommercial. · updated 2026-08-08); Related: agent-audit · aguara

In 2 lists

skill-scanner

🟠 — Scanner for agent skills combining YAML + YARA patterns, LLM-as-a-judge, and behavioral dataflow analysis (Codex / Cursor skill formats). (Cisco AI Defense) · updated 2026-08-04); Related: defenseclaw · aguara · Cisco AI Defense – mcp-scanner

mcp-scanner

🟢⚠️ — Scanner for MCP servers and agentic tool surfaces, covering tools, prompts, resources, package risk, malware indicators, and deployment readiness. (Cisco AI Defense) · updated 2026-08-07); Related: Cisco AI Defense – skill-scanner · Snyk Agent Scan · aguara

mcp-guardian

🟢 — JS/TS library and CLI for detecting prompt injection in MCP tool descriptions and pinning tool definitions. · updated 2026-07-29); Related: Cisco AI Defense – mcp-scanner · Snyk Agent Scan

MCP Observatory

🟢🟠 — CI-native MCP-server testing tool for schema drift, safe attack simulation, record/replay verification, health scoring, and SARIF evidence before agents depend on a server. (KryptosAI) — note: the local evidence engine is open source; hosted telemetry intelligence, fleet workflows, and…;…

agentic-radar

🟠 — CLI security scanner for agentic workflows (LangGraph, CrewAI, n8n, etc.) — maps tools/data flows and flags risks. (SplxAI) · updated 2025-11-27)

In 6 listsDetails

skilltotal

🟢 — Offline deterministic static scanner (regex + AST, no LLM, no account) for AI components — agent skills/plugins, MCP servers, npm & PyPI packages, and git repos; flags supply-chain risk, dangerous capabilities, prompt-injection surfaces, MCP tool poisoning/shadowing, and data-exfiltration…;…

Sunglasses

🟢 — Local input/content scanner for AI agents that checks prompts, files, media metadata, skills, and tool descriptions against pattern and mechanism-based prompt-injection, exfiltration, command-injection, and agent-threat rules. — note: early-stage project; published precision/recall…

trentclaw

🟠 — Client-side security auditor for OpenClaw deployments: applies pattern-based secret redaction locally, then uploads config/skill metadata and confirm-gated skill archives to Trent AI's API, which identifies misconfigurations, risky skills (prompt injection, permission escalation, data…

A2A Security Scanner

🟢 — CLI and PyPI scanner for Agent-to-Agent (A2A) agent cards, source code, registries, and live endpoints using specification validation, YARA rules, heuristics, endpoint testing, and an optional LLM analyzer. (Cisco AI Defense) · updated 2026-04-16); Related: Cisco AI Defense – mcp-scanner ·…

Ship Safe

🟢🟠 — Local security CLI for application code, AI-agent and MCP configuration, secrets, dependencies, CI, and cloud/IaC surfaces, with deterministic checks, optional AI-assisted analysis, and SARIF output. — note: the MIT CLI works without an account for its core checks; optional AI modes can…;…

AgentSeal

🟠⚠️ — Agent-security CLI and runtime library for scanning MCP servers, skills, prompts, and configuration, plus local guard and monitoring workflows with optional model-assisted red teaming. — note: source-available under FSL-1.1-Apache-2.0 rather than an OSI-approved open-source license;…

SlowMist Agent Security

🟢 — Security-review skill and workflow for auditing agent skills, MCP servers, repositories, URLs, and documents before installation or use. (SlowMist) — note: Markdown-based workflow skill executed by a compatible host agent, not a deterministic standalone scanner; findings depend on the…;…

Sandbox Probe

🟢 — Static Go probe that measures the effective filesystem, network, process, credential, and runtime capabilities exposed inside an AI-agent sandbox, then compares sandbox and host baselines. (ControlPlane) — note: boundary-measurement auditor, not an enforcement layer; some integration…

AI Agent & Coding-Agent Security >Frameworks, Rule Standards & Benchmarks

Project CodeGuard

🟢⚠️ — Model-agnostic secure-coding rules and skills framework with translators for popular coding agents, validators, release artifacts, and an MCP server for centrally distributing the rules. (CoSAI / OASIS) — note: framework and ruleset, not a deterministic scanner or runtime enforcement…

asamm

🔬 — Agentic SAMM — an OWASP SAMM extension for AI-driven development: an entry-point-based threat taxonomy plus 17 controls across 5 SAMM functions (Governance, Design, Implementation, Verification, Operations) with L1/L2/L3 maturity. License: CC BY-SA 4.0. (CyberOK / S. Gordeychik) · updated…;…

agent-threat-rules (ATR)

🟢 — Open, versioned, machine-readable detection rules for AI-agent threats (prompt injection, tool poisoning, MCP attacks, and skill compromise) — "Sigma for agents"; 768 rules across 10 categories with integrations for Microsoft AGT, Cisco AI Defense, MISP, OWASP, FINOS, and SigmaHQ. · updated…;…

In 3 lists

Agent Governance Toolkit

🟢 — Multi-language toolkit for policy-enforced agent tool calls and audit records, with optional identity, MCP-gateway, sandboxing, reliability, and compliance components. (Microsoft) — note: official public preview; APIs and deployment patterns may change before general availability. · updated…;…

In 5 listsDetails

MCP-Security-Checklist

🟢 — Security checklist for MCP clients, servers, multi-MCP deployments, lifecycle controls, authz/authn, isolation, and crypto-specific MCP integrations. (SlowMist) · updated 2025-04-28); Related: Cisco AI Defense – mcp-scanner · ATR – Agent Threat Rules

Anthropic-Cybersecurity-Skills

🟢 — Large community cybersecurity skill library for AI agents, mapped to MITRE ATT&CK, NIST CSF, MITRE ATLAS, D3FEND, and NIST AI RMF. — note: independent community project, not affiliated with Anthropic. · updated 2026-08-08); Related: sast-skills · Cisco AI Defense – skill-scanner

In 4 listsDetails

Claude-BugHunter

🟢 — Claude Code / agent-skill bundle for authorized bug hunting and external red-team workflows across web, API, identity, cloud, recon, reporting, Burp MCP, slash commands, and the cbh CLI. — note: skill bundle and workflow knowledge base, not a standalone scanner. · updated 2026-08-17);…

AgentDojo

🟢🔬 — Benchmark environment for prompt-injection attacks and defenses in tool-using LLM agents. · updated 2026-06-02); Related: agent-audit · ATR – Agent Threat Rules

Agent3Sigma-Canary

🟢🔬 — Sandboxed research framework for evaluating AI-agent security over complete execution trajectories, covering direct/indirect injection, skill and memory poisoning, and practical risk outcomes. (Ant Group) — note: research framework that requires Docker plus target and auxiliary LLM…;…

Agent Security Bench (ASB)

🟢🔬 — Official ICLR 2025 benchmark for evaluating attacks and defenses in LLM-based agents across ten scenarios, including direct and indirect prompt injection, memory poisoning, and defensive strategies. — note: research benchmark rather than a production control; reproducing evaluations…;…

Skill-Inject

🟢🔬 — Benchmark for measuring prompt-injection vulnerabilities carried by agent skill files across Claude Code, Codex CLI, and Gemini CLI under multiple safety-policy conditions. — note: benchmark artifact that executes controlled malicious skill scenarios; run only in an isolated test…; Related:…

AI Security Verification Standard (AISVS)

🔬⚠️ — Stable verification standard defining testable security requirements for AI applications across model lifecycle, supply chain, data handling, agentic systems, and MCP integrations. (OWASP) — note: security standard and checklist, not an executable scanner; share-alike terms apply to…

OWASP Agent Security Regression Harness

🟢 — Vendor-neutral harness for running repeatable agent and MCP abuse scenarios, evaluating policy assertions over execution traces, and emitting machine-readable regression results for local development and CI. (OWASP) — note: early OWASP Incubator project; it is a regression harness for known…;…

AI Agent & Coding-Agent Security >Runtime Protection & Enforcement

OpenShell

🟢 — Policy-governed runtime for autonomous and coding agents with container or microVM-backed sandboxes, filesystem/process/network controls, endpoint-bound credential injection, and audit logs. (NVIDIA) — note: pre-release runtime whose effective isolation depends on the selected compute…

In 4 listsDetails

Numbat

🟢 — Endpoint-local visibility and detection for AI-agent activity across hooks, plugins, OTLP, and on-disk artifacts, with CEL rules, multi-step sequence detections, and forensic reconstruction. (Perplexity AI) — note: monitoring is the default posture; blocking is opt-in, limited to supported…

agentsh

🟢 — Execution-layer policy shell for AI agents that intercepts file, network, process, signal, and selected database activity and emits structured audit events. (Canyon Road) — note: the shell shim bypasses policy for non-TTY stdin unless --force is used, which is critical for headless agents and…

In 2 lists

brood-box

🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…

In 6 listsDetails

Greywall

🟢 — Kernel-enforced filesystem, network, syscall, and command-policy wrapper for coding agents on Linux and macOS, with a separate traffic-observability mode and least-privilege profile generation. (Greyhaven) — note: deny-by-default applies to greywall; greywatch is intentionally permissive and…

In 2 lists

nono

🟢 — Least-privilege sandbox for AI coding agents that isolates the agent and delegated tools with composable filesystem, network, credential-proxy, and command policies. (NoLabs) — note: APIs are still stabilizing ahead of the 1.0 release; review every pulled profile before use. · updated…;…

cplt

🟢 — Kernel-backed sandbox wrapper for AI coding agents that applies Seatbelt on macOS or Landlock and seccomp on Linux, content-pins approvals for repository policy, filters environment and resource access, and gates selected git and GitHub commands. (NAV (Norwegian Labour and Welfare…; Related:…

Arcjet Guard

🟢🟠 — JavaScript runtime guard for AI-agent tool calls and MCP handlers, with prompt-injection detection, sensitive-data detection/redaction, and custom local policy rules. (Arcjet) — note: open SDK packages integrate with Arcjet's hosted platform; assess the service, account, and…

ToolHive

🟢 — Platform for running MCP servers in isolated containers with per-request identity/access policy, registry and gateway workflows, audit logs, Kubernetes operator support, and observability hooks. (Stacklok) · updated 2026-08-14); Related: microsandbox · defenseclaw

In 3 lists

Pipelock

🟢 — AI-agent firewall and verifiable egress-control layer mediating HTTP, WebSocket, CONNECT, MCP, and A2A traffic to detect prompt injection, secret exfiltration, SSRF, and suspicious outbound actions. — note: open-source core is Apache-2.0; commercial reporting/features are also advertised. ·…;…

node9

🟢 — Local policy and human-approval gate for supported coding-agent tool calls routed through agent hooks or an MCP wrapper, with credential-path checks, secret detection, and audit logging. (Node9) — note: cooperative hooks/MCP enforcement, not process isolation or a complete credential…;…

In 2 lists

SourceryKit

🟠⚠️ — Python SDK for agent guardrails that intercepts outbound HTTP calls, enforces trusted-endpoint policies, logs requests, and checks agent handoff claims against a Provably backend before propagation. (ProvablyAI) — note: BSL-1.1 licensed; requires Provably backend/API credentials and…;…

emisar

🟠⚠️ — Agent-infrastructure control plane that exposes declared, typed actions through MCP, applies policy and approval gates before dispatch, revalidates calls on an outbound-only host runner, and records separate control-plane and host audit trails. — note: runner, MCP bridge, and packs are…

mcp-context-protector

🟢 — MCP security wrapper that sits in front of downstream MCP servers, scans tool responses with guardrail providers, and supports quarantine/review workflows for desktop and coding-agent MCP configs. (Trail of Bits) · updated 2026-02-13); Related: Cisco AI Defense – mcp-scanner · ToolHive ·…

MCP Defender

🟢⚠️ — Desktop app that proxies MCP tool-call requests and responses for Cursor, Claude, VS Code, and Windsurf, checks intercepted traffic against signatures, and prompts users to allow or block suspicious calls. — note: AGPL-3.0 licensed; project has been acquired by Docker. · updated…

MCP Gateway

🟢 — Plugin-based MCP gateway that proxies configured MCP servers, sanitizes sensitive request/response data, supports guardrail plugins such as basic masking and Presidio, and runs a server reputation/risk check before loading MCP servers. (Lasso Security) · updated 2026-01-22); Related: ToolHive…

Parallax

🟢 — Rust runtime policy engine for AI agents: evaluates lifecycle events with regex, keyword, Sigma, CEL, and SQL rules to block or redact prompt injection, data exfiltration, dangerous tool calls, and secret leakage. — note: early-stage project with limited adoption signal. · updated…

Armorer Guard

🟢 — Local Rust scanner and MCP proxy for AI-agent prompt injection, credential leakage, exfiltration, and risky tool-call arguments, with structured reasons and no scanner network calls. — note: young project with limited independent adoption signal. · updated 2026-08-09); Related: agentguard ·…

onecli

🟢 — Credential gateway and encrypted vault for AI agents; injects real API credentials at the gateway so agents only see placeholder keys. · updated 2026-07-31); Related: agentguard · defenseclaw

In 2 lists

microsandbox

🟢 — Local-first, microVM-backed programmable sandboxes for AI agents with SDKs, CLI, MCP support, and rootless hardware isolation. · updated 2026-08-17); Related: agentguard · defenseclaw

In 3 lists

agentguard

🟢 — Real-time security layer for coding agents: hooks scan every new skill, block dangerous actions before execution, run daily posture patrols, and track which skill triggered each action (incl. Web3-specific checks). · updated 2026-06-25); Related: agent-audit · defenseclaw

defenseclaw

🟠 — Enforcement and evidence layer for agentic deployments: static CodeGuard checks, sandboxing, registry ingestion with SSRF guards, and audit/observability. (Cisco AI Defense) · updated 2026-08-17); Related: Cisco AI Defense – skill-scanner · agentguard

clawsec

🟢⚠️ — Security skill suite for OpenClaw-family agents; AGPL-3.0 licensed. (Prompt Security) · updated 2026-08-05); Related: agentguard · Cisco AI Defense – skill-scanner

In 2 lists

AgentLock

🟢🔬⚠️ — Pre-action authorization gate for LLM agent tool calls that decides from session provenance rather than content, with deny-by-default tool permissions, parameter lineage, Ed25519 signed receipts, and a hash-chained audit log; AGPL-3.0 licensed with commercial options. — note: evaluated on…

h5i

🟢 — Local Rust CLI for auditable coding-agent workspaces: per-agent worktrees with sandbox policies, provenance capture, peer review, neutral verification, secret/prompt-injection audit signals, and refs/h5i/* run metadata. — note: security-adjacent agent-workspace governance tool, not a…;…

DvalinCode

🟢 — Local-first AI coding agent with runtime governance controls: org/repo policy gates for tools, models, MCP servers, paths, and commands, plus provider/shell/MCP egress controls and hash-chained audit logs. — note: young project with limited independent adoption signal. · updated 2026-08-17);…

In 2 lists

TAP

🟢🟠 — Credential-isolation proxy and MCP server for AI agents: agents send placeholder credentials, TAP injects real secrets server-side after per-action policy checks, with optional human approval on sensitive calls. (human.tech) — note: Apache-2.0 runtime is self-hostable, but the hosted…

Agent Memory Guard

🟢 — Runtime middleware for AI-agent memory reads and writes, screening prompt injection, memory poisoning, secret/PII leakage, protected-key tampering, and size anomalies before persisted memory is reused. (OWASP) — note: OWASP Incubator project; published benchmark numbers are project-reported…

In 3 lists

AIO Sandbox

🟢⚠️ — All-in-one Docker workspace for AI agents with browser, shell, file, code-execution, MCP, and VSCode interfaces, plus API-key/JWT controls and private-deployment guidance. — note: the public repository ships SDKs, integrations, and docs rather than the core runtime service; official…;…

In 3 lists

Agentgateway

🟢 — Agent-native proxy and gateway for MCP and A2A traffic with OAuth/JWT/API-key authentication, CEL-based RBAC policies, TLS, rate limiting, and OpenTelemetry observability. · updated 2026-08-14); Related: MCP Gateway · Pipelock

In 4 listsDetails

Kubernetes Agent Sandbox

🟢 — Kubernetes CRDs and controllers for isolated, stateful singleton agent workloads, delegating low-level isolation to configured runtimes such as gVisor or Kata Containers. (Kubernetes SIG Apps) — note: sandbox orchestrator, not an isolation runtime itself; security depends on the selected…;…

In 2 lists

Prismor

🟢 — Self-hosted runtime control plane for coding agents with pre-tool-call hooks, policy-driven observe/approve/block decisions, an MCP gateway, secret and egress controls, and tamper-evident audit evidence. · updated 2026-08-16); Related: Armorer Guard · AgentLock

Gram

🟢🟠⚠️ — Open-source stack behind Speakeasy's AI control plane that centrally manages MCPs, Skills, and Assistants with granular permissions, policy enforcement, threat detection, and observability. (Speakeasy) — note: AGPL-3.0 copyleft license; Gram is also available as Speakeasy's hosted…

tirith

🟢⚠️ — Terminal guard for developers and AI coding agents that intercepts homograph and terminal-injection tricks, obfuscated execution chains, pipe-to-shell patterns, credential exfiltration, and malicious skill/config files. — note: AGPL-3.0 with a separate commercial license; shell…

ADR

🟢🔬 — Agentic AI Detection and Response system combining cross-client agent telemetry, ADR-Bench security scenarios, and a dual-agent detector for suspicious intent, tool use, and execution traces. (Uber) — note: deployed at Uber and published with an MLSys 2026 paper; the open release includes…;…

In 2 lists

xaidr

🟢 — In-process runtime security sensor for AI agents that inspects input, tool calls, output, and agent-to-agent envelopes inside the agent process, with structured shell-command classification, YAML policy, privilege tiers, an opt-in circuit breaker, and OpenTelemetry export. (Delphi Security)…

Agentmetry

🟢 — Local-first flight recorder for AI coding agents and MCP servers that writes a hash-chained JSONL trail with RFC 6962 Merkle roots, applies MITRE-mapped sequence detection across a session, attests every 300s which agent surfaces are covered, uncovered, absent or unknown, and forwards to…;…

piighost

🟢 — Local runtime pseudonymization layer that replaces detected PII with stable placeholders before model calls and restores the original values in responses and selected tool arguments, with integrations for LangChain, Pydantic AI, LlamaIndex, and OpenAI-compatible clients. — note: reversible…;…

HOL Guard

🟢🟠 — Local-first runtime security layer for coding agents that evaluates commands, package installs, skills, MCP configuration, and sensitive actions through policy, approval, evidence, and audit workflows. (Hashgraph Online) — note: integrations are cooperative hooks rather than a hard…;…

StackOne Defender

🟢 — Offline TypeScript runtime guard for indirect prompt injection in tool results, using bundled ONNX classifiers, deterministic checks, sanitization, and allow/block verdicts. (StackOne) — note: blocking high-risk results is opt-in by default; missing Tier-2 dependencies can fall back to…;…

In 2 lists

Earl

🟢 — Capability proxy for AI agents that exposes approved operation names while keeping request templates and credentials outside the model, with HCL policy, audit, and egress controls. (Mathematic) — note: operation templates and policy configuration form part of the trusted boundary and…

Bifrost

🟢🟠 — Apache-licensed AI and MCP gateway with multi-provider routing, virtual-key access controls, budgets, rate limits, MCP aggregation, OAuth, automatic fallbacks, and load balancing. (Maxim) — note: model-provider credentials and proxied request/response data are sensitive; restrict and…;…

In 8 listsDetails

Portkey AI Gateway

🟢🟠 — Open AI gateway with provider routing, fallback and retry controls, guardrail integrations, observability, and MCP traffic support for model and agent applications. (Portkey) — note: the gateway is general infrastructure rather than a standalone security scanner; model-provider…

In 6 listsDetails

Casbin AI Gateway

🟢 — Local gateway and policy layer for model-provider and MCP traffic, combining provider-key mediation, access control, prompt records, and configurable request handling. (Apache Casbin) — note: binds to localhost by default because its local UI can exercise administrative operations and the…;…

Adrian

🟢🟠 — Runtime monitoring and intervention layer that correlates agent actions with available reasoning traces through Python and TypeScript SDKs, a Claude Code integration, and managed or self-hosted deployments. (Secure Agentics) — note: the bundled self-hosted stack requires Docker,…

Sandlock

🟢 — Unprivileged Linux process sandbox using Landlock, seccomp-BPF, and seccomp user notification to apply per-process filesystem, network, syscall, and execution policies without a container or VM. (Multikernel) — note: Linux-kernel process isolation rather than prompt-injection detection;…;…

Lunar

🟢🟠 — API and MCP gateway combining outbound-traffic visibility, policy enforcement, rate limits, retries, circuit breakers, and centralized MCP server aggregation for agent workloads. (Lunar.dev) — note: the repository is active but its latest formal GitHub release is from 2024; the README…;…

Norviq

🟢 — Kubernetes policy enforcement point for LLM agent tool calls that content-hash pins each tool definition at discovery and evaluates every tools/call against OPA/Rego policy before the upstream MCP server receives it. — note: ships in audit mode — the installed baseline records what it would…;…

sofagent

🟢 — Commit-time audit and governance suite for AI coding agents that scans git diffs against deterministic rules, records local audit history, and exposes MCP tools for governance aggregation. — note: HMAC signing is optional, while local hooks, configuration, and key material remain accessible…;…

In 2 lists

AI/ML Supply Chain & Model Security

AI BOM

🟢 — Inventories models, agents, tools, MCP clients and servers, datasets, prompts, guardrails, secrets, and cloud AI resources, with CycloneDX 1.6 output and policy workflows. (Cisco AI Defense) — note: core inventory is distinct from the narrower model-file AIsbom already listed; the extended…;…

Fraim

🟢 — Framework for AI-powered security workflows including LLM SAST and IaC analysis with SARIF/HTML output. · updated 2025-12-01); Related: sast-skills

Adversarial Robustness Toolbox (ART)

🟢 — Flagship machine-learning security library for evaluating and defending models against evasion, poisoning, extraction, and inference attacks across major ML frameworks. (LF AI & Data / IBM) · updated 2025-11-13); Related: Foolbox · PrivacyRaven

In 4 listsDetails

Foolbox

🟢 — Classic Python toolbox for generating adversarial examples and benchmarking robustness of PyTorch, TensorFlow, and JAX models. · updated 2024-03-04); Related: Adversarial Robustness Toolbox

In 3 lists

modelscan

🟢 — Scans ML model files for unsafe serialization patterns and embedded code, with a focus on model serialization attacks. (Protect AI) · updated 2026-02-18); Related: Fickling · picklescan · ai-exploits

Fickling

🟢 — Python pickle decompiler, rewriter, and static analyzer for inspecting and detecting malicious pickle/PyTorch payloads. (Trail of Bits) · updated 2026-08-13); Related: modelscan · picklescan

picklescan

🟢 — Lightweight CLI/library for detecting suspicious Python pickle operations in ML and model artifacts. · updated 2026-07-01); Related: modelscan · Fickling

AIsbom

🟢 — AI software bill of materials tooling for AI/ML supply-chain inventory and provenance metadata. · updated 2026-08-17); Related: modelscan · model-provenance-kit

model-provenance-kit

🟢 — Toolkit for model-family provenance and fingerprinting across model weights, tokenizers, and architecture signals. (Cisco AI Defense) · updated 2026-08-12); Related: AIsbom

pickle-fuzzer

🟢 — Structure-aware fuzzer for pickle scanners, useful for hardening tools such as modelscan, Fickling, and picklescan. (Cisco AI Defense) · updated 2026-08-03); Related: modelscan · Fickling · picklescan

Medusa

🟢⚠️ — AI-first security scanner for AI/ML repos, agents, and MCP surfaces; AGPL-3.0 licensed. (Pantheon Security) · updated 2026-06-24); Related: agent-audit · modelscan

PrivacyRaven

🟢🔬 — Privacy-testing library for deep-learning systems, covering model extraction and membership-inference style attacks. (Trail of Bits) — note: archived/hiatus project, but still a useful reference implementation. · updated 2025-09-05); Related: Adversarial Robustness Toolbox

In 2 lists

gym-malware

🟢🔬 — OpenAI Gym environment for reinforcement-learning agents that mutate PE malware to evade static ML malware detectors. · updated 2018-06-15)

In 2 lists

deep-pwning

🟢🔬 — Historical "Metasploit for machine learning" framework for experimenting with adversarial robustness of ML models. · updated 2022-05-17)

open-malicious-code-benchmark

🟢🔬 — OMCBench benchmark suite for malicious-code/package detection: labeled Python and JavaScript package archives, common runners, and published precision/recall/F1 metrics. (False Positive Community) — note: evaluates an unreleased commercial ML detector (MOLOT / PT Application Inspector)…;…

malicious-software-packages-dataset

🟢🔬 — Human-vetted dataset of malicious software packages across npm, PyPI, IDE extensions, and AI Skills, useful for detector training and evaluation. (Datadog Security Labs) — note: contains real malware samples; Datadog notes selection bias because many samples were identified by GuardDog. ·…;…

GuardDog

🟢 — CLI for detecting malicious PyPI, npm, Go, RubyGems, GitHub Actions, and VSCode extension packages using Semgrep rules and package-metadata heuristics. (Datadog) · updated 2026-08-14); Related: malicious-software-packages-dataset · Packj

In 2 lists

package-analysis

🟢🔬 — Sandboxed static/dynamic analysis pipeline for open-source packages, capturing filesystem, process, and network behavior and publishing data for malicious-package research. (OpenSSF) · updated 2026-07-21); Related: malicious-packages · package-feeds

malicious-code-ruleset

🟢 — Focused Semgrep ruleset for malicious-code patterns such as dynamic execution and obfuscation, used as an OMCBench baseline. (Apiiro) · updated 2025-02-24); Related: open-malicious-code-benchmark

pypi_malregistry

🔬⚠️ — ASE'23 / USENIX Security'26 malicious-PyPI dataset with more than 10k malicious package versions. — note: no LICENSE file found and the repository contains malware samples; handle in an isolated environment. · updated 2026-07-21); Related: malicious-software-packages-dataset

Activation-based Model Scanner (AMS)

🟢🔬 — PyPI scanner that uses safety-related activation fingerprints to detect degraded or removed safety training and compare an open-weight model with a known baseline. (Google Cloud Platform) — note: unofficial and unsupported Google research-derived project; GPU execution is recommended,…;…

Pentest & Red-Team Agents

PentestGPT

🟢🔬 — The original USENIX'24 LLM pentest agent; re-released as an autonomous pipeline with strong benchmark results. · updated 2026-07-14)

In 6 listsDetails

PentAGI

🟢 — Fully autonomous multi-agent pentest framework with Docker sandboxing. (VXControl) · updated 2026-08-06)

In 5 listsDetails

CAI – Cybersecurity AI

🟢🟠 — Modular, bug-bounty-ready agent framework supporting 300+ LLM models. MIT for research; separate commercial license for production/on-prem. (Alias Robotics) · updated 2026-07-14)

In 4 listsDetails

Strix

🟢 — Autonomous "AI hackers" that dynamically run code and validate vulnerabilities with PoCs (Apache-2.0). · updated 2026-08-17)

In 3 lists

hackingBuddyGPT

🟢🔬 — Minimal (~50 LOC) research framework for LLM-driven Linux priv-esc and web pentesting (FSE'23). · updated 2026-08-10)

Nebula

🟢🟠 — AI pentesting CLI assistant with local-LLM support (Llama-3.1, Mistral, DeepSeek). · updated 2026-07-26)

HexStrike-AI

🟢 — MCP server exposing 150+ security tools (nmap, gobuster, nuclei, …) to AI agents (MIT). · updated 2026-08-03)

In 3 lists

Deep Eye

🟢 — AI-assisted penetration-testing scanner that orchestrates multiple LLM providers for payload generation, 45+ vulnerability checks, CVE/RAG-assisted testing, AI triage, scan diffing, browser automation, proxying, and multi-format reports. — note: MIT-licensed; authorized use only. Heavy…;…

In 2 lists

Burp Suite MCP Server

🟢⚠️ — Official Burp Suite extension exposing Burp to AI clients through MCP. (PortSwigger) — note: GPL-3.0 licensed. · updated 2026-08-12); Related: HexStrike-AI

In 2 lists

pentest-ai

🟢 — Offensive-security MCP server with 200+ wrapped tools, specialist agents, and OWASP-oriented probes for authorized testing. · updated 2026-08-17); Related: pentest-ai-agents

pentest-ai-agents

🟢 — Collection of Claude Code offensive-security subagents for authorized penetration-testing research. · updated 2026-08-16); Related: pentest-ai

DarkMoon

🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…

In 10 listsDetails

T3MP3ST

🟢⚠️ — Autonomous offensive-security meta-harness that wraps local or API-backed coding agents into a multi-agent recon-to-exploit workflow with MCP/API, War Room UI, tool arsenal, and committed benchmark artifacts. — note: very new AGPL-3.0 project with bold benchmark claims; use only for…;…

In 3 lists

Shannon

🟢🟠⚠️ — White-box autonomous AI pentester with strong XBOW-benchmark results. Shannon Lite is AGPL-3.0; Shannon Pro is commercial. · updated 2026-08-12)

In 2 lists

AIDA

🟢⚠️ — Model-agnostic autonomous pentest agent running inside an isolated Docker environment; AGPL-3.0 licensed. · updated 2026-07-19)

HackSynth

🟢🔬⚠️ — Planner/summarizer LLM-agent framework for autonomous penetration testing and benchmark evaluation; AGPL-3.0 licensed. · updated 2025-06-24)

In 2 lists

VulnBot

🟢🔬 — Multi-agent collaborative penetration-testing framework with RAG support. · updated 2025-04-07)

PentestAgent

🟢 — Black-box AI pentest framework with MCP, multi-agent spawning, and persistent sessions. · updated 2026-08-04)

In 2 lists

cyber-security-llm-agents

🟢⚠️ — AutoGen-based agents for cybersecurity tasks (shown at RSAC 2024). (NVISO) · updated 2024-05-07)

In 2 lists

Pentest-Swarm-AI

🟢 — Swarm-intelligence multi-agent pentest with stigmergic blackboard coordination (Go). · updated 2026-08-04)

hackGPT

🟢⚠️ — LLM offensive-security toolkit. · updated 2026-08-12)

In 2 lists

ShiftGrid

🟢 — Prompt engine that turns Claude Code into a transparent, human-in-the-loop pentester, structuring engagements through checklists, observations, and notes exposed via an agent-facing API. — note: early-stage local Docker application with no built-in authentication; keep its API and UI ports…

BugTraceAI

🟢⚠️ — Self-hosted autonomous web-application security scanner that combines reconnaissance, specialist exploit agents, Go fuzzers, and Playwright validation to produce evidence-backed findings. (BugTraceAI) — note: AGPL-3.0 licensed and beta; use only for authorized testing. Requires an LLM…;…

HunterX

🟢 — AI-assisted offensive security engine that orchestrates reconnaissance, security-tool coordination, vulnerability detection and validation, evidence collection, and report-ready findings in one workflow. (NullC0d3) — note: early-stage and tool-orchestration-heavy; run only in an isolated,…

MCP Security Hub

🟢 — Collection of Dockerized MCP servers that expose offensive-security tools such as Nmap, Nuclei, SQLMap, Ghidra, Hashcat, and related assessment utilities to MCP-capable assistants. (FuzzingLabs) — note: orchestration and wrapper collection rather than a security boundary; its containers…;…

Forefy .context

🟢 — MIT-licensed collection of AI-agent Skills, Goals, and Dynamic Workflows for security auditing, authorized penetration testing, and research across web, cloud, blockchain, and defensive workflows. (Forefy) — note: agent-interpreted skill and workflow bundle rather than a deterministic…;…

AI-Powered Recon & Narrow ML Tools >Subdomain & DNS Prediction

subwiz

🟢 — 🅐 Lightweight nanoGPT model that predicts resolvable subdomains via beam search; model weights are published on Hugging Face. (Hadrian Security) · updated 2025-12-18); Related: HadrianSecurity/subwiz model

regulator

🟢⚠️ — 🅐 Learns and ranks regex-like naming patterns from known subdomains to generate likely new candidates. — note: no LICENSE file found; treat as source-available until clarified. · updated 2023-02-18); Related: subwiz

AI-Powered Recon & Narrow ML Tools >Recon Screenshot Triage

eyeballer

🟢⚠️ — 🅐 Convolutional neural network that classifies pentest/recon screenshots (login pages, webapps, old-looking sites, parked domains, and custom 404s) for attack-surface triage. (Bishop Fox) — note: GPL-3.0 licensed. · updated 2024-02-19)

In 3 lists

AI-Powered Recon & Narrow ML Tools >Software / Tech Fingerprinting

GyoiThon

🟢🔬 — 🅐 Machine-learning-assisted web intelligence tool that fingerprints products, versions, CVEs, login pages, debug messages, and related web-server signals from HTTP responses. — note: historical research reference; Apache-2.0 licensed, but maintenance is low. · updated 2021-06-29)

In 2 lists

AI-Powered Recon & Narrow ML Tools >AI-Assisted Fuzzing

ffufai

🟢⚠️ — 🅑 AI wrapper around the ffuf web fuzzer that suggests file extensions and paths from the target URL and headers using OpenAI or Anthropic models. (Joseph Thacker) — note: requires an LLM API key; README states MIT but no LICENSE file was found. · updated 2025-12-04)

AI-Powered Recon & Narrow ML Tools >Password / Credential ML

PassGPT

🔬⚠️ — 🅐 GPT-style password model trained on leaked passwords for research on password generation and strength estimation. (Rando et al.) license: CC BY-NC-4.0 · access: open 10-char model; 16-char variant gated · artifacts: PyTorch/Safetensors. Research-only / non-commercial use; related code:…

PassGAN

🔬 — 🅐 WGAN that learns password distributions from leaks to generate guesses; historical reference implementation of the PassGAN paper (MIT). — note: historical research reference; not an actively maintained password-auditing product. · updated 2018-09-30)

neural_network_cracking

🔬 — 🅐 RNN password-guessing model from Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks (USENIX Security 2016); Apache-2.0 licensed. (CMU CUPS Lab) — note: historical USENIX research implementation, not a maintained password-auditing product. · updated 2018-11-30);…

In 2 lists

AI-Powered Recon & Narrow ML Tools >Phishing Detection (Visual / URL)

phishing-url-detection

🟢 — 🅐 Packaged URL phishing classifier with ONNX and pickle artifacts. license: MIT · access: open · artifacts: ONNX, pickle. Model card recommends ONNX over pickle for safer inference.

Phishing Email Detection DistilBERT v2.4.1

🟢 — DistilBERT text-classification model for email and URL phishing detection, trained on a public Hugging Face phishing-email dataset. license: Apache-2.0 · access: open · artifacts: Safetensors. — note: strong download signal, but independently verify the very high published metrics before…

PhishIntention

🔬 — 🅐 Deep-vision phishing detector that infers both brand intention and credential-taking intention from webpage appearance and dynamics (USENIX Security 2022). — note: CC0-1.0 licensed. · updated 2026-06-04)

VisualPhishNet

🔬⚠️ — 🅐 Triplet CNN for zero-day phishing detection by visual similarity to trusted websites (ACM CCS 2020). (CISPA) — note: no LICENSE file found; dataset access is research-request based. · updated 2022-02-09)

AI-Powered Recon & Narrow ML Tools >AI/ML-Assisted Detection Rules & Engines

SYARA

🟢🔬 — 🅐 Semantic YARA-like rule engine for text and multimodal signals, adding embedding similarity, classifier-backed rules, LLM evaluators, and pHash matching to familiar YARA-style syntax. — note: early-stage engine; useful for LLM-era intent signals such as phishing, prompt injection,…

AutoYara

🟢🔬 — 🅐 Research implementation of automatic YARA rule generation via biclustering over byte n-grams for malware-family samples. — note: Apache-2.0 research code from the ACM AISec 2020 paper; README explicitly says it comes with no warranty or support. · updated 2025-10-08); Related: Automatic…

yaraml_rules

🟢🔬 — Research code that trains scikit-learn classifiers on malware and benign corpora, then compiles the learned model into deployable YARA rules. (Sophos) — note: historical research reference; the maintained value is the ML-to-YARA technique, not a current detection product. · updated…

RuleLLM

🟢🔬 — 🅑 LLM-assisted malware-rule generator that clusters malicious code samples and produces/refines/validates YARA and Semgrep rules. — note: MIT-licensed research prototype; requires OpenAI-compatible API access plus YARA/Semgrep validators. · updated 2025-04-25)

AI-Powered Recon & Narrow ML Tools >Defensive Trained-Model Detectors

DeepSQLi

🟢⚠️ — 🅐 Deep-learning SQL-injection detector with dataset, trained models, and a Flask Prediction API for GatewayD IDS/IPS integration. (GatewayD) — note: AGPL-3.0 licensed; defensive detector rather than offensive generator. · updated 2026-02-21)

deepsecrets

🟢 — Semantic secrets scanner using lexing/parsing, entropy checks, and hashed-known-secret matching across 500+ languages. — note: useful narrow detector, but not a trained ML model. · updated 2026-06-04)

VLAI Vulnerability Severity Classifier

🟢🔬 — RoBERTa-based vulnerability-severity classifier trained on CIRCL vulnerability scores to assist triage before manual CVSS scoring. (CIRCL) license: CC-BY-4.0 · access: open · artifacts: Safetensors.

AI-Powered SAST & Secure Code Review

Cloudflare Security Audit Skill

🟢 — Coding-agent skill for a multi-phase source-security audit with reconnaissance, coverage-led hunting, independent verification, structured findings, and a separate record-validation pass. (Cloudflare) — note: workflow skill, not a standalone scanner; it requires a capable coding agent with…;…

In 3 lists

Mantis

🟢🔬 — Security-review skills and an ADK reference harness for vulnerability discovery, triage, reproduction, patching, and deterministic verification gates. (Google) — note: can generate and execute code while reproducing findings; use only on authorized source in an isolated restricted…;…

VulnHunter (Capital One)

🟢 — Attacker-oriented source-review workflow with forward analysis from exposed entry points, a finding-falsification pass, evidence-backed remediation, and a separate fix-verification flow. (Capital One) — note: built and optimized for Claude Code with an Opus-class model, so source context is…;…

Vulnhuntr

🟢 — Zero-shot vulnerability discovery in Python repos via LLM call-chain analysis; credited with a 0-day RCE in Ragflow. (Protect AI) · updated 2025-02-06); Related: IRIS

deepsec

🟢 — Agent-powered security harness for scanning large codebases with coding agents, resumable parallel runs, custom matchers, and optional revalidation. (Vercel Labs) · updated 2026-08-13); Related: claude-code-security-review · sast-skills

In 2 lists

Codex Security

🟠 — CLI and TypeScript SDK that use Codex Security to find, validate, and help fix vulnerabilities in a codebase, with scan comparison and containerized bulk-scan support. (OpenAI) — note: the CLI/SDK are open source, but scans require Codex Security access and, for best results, OpenAI Trusted…;…

In 3 lists

open·kritt

🟢⚠️ — Self-hosted platform that orchestrates Codex or Claude Code across focused vulnerability-research workflows, then validates, de-duplicates, ranks, and reports resulting findings. (Kritt AI) — note: jobs run as root in disposable Docker containers with writable target copies and direct…;…

Visa Vulnerability Agentic Harness

🟢 — Agentic SAST pipeline for autonomous vulnerability discovery, exploitability verification, SARIF/Markdown reporting, remediation, and validation using frontier AI models. (Visa) — note: Apache-2.0; authorized use only. The default scan profile can continue into remediation and edit target…;…

In 2 lists

defending-code-reference-harness

🟢 — Reference Claude Code skills and autonomous vulnerability-discovery pipeline for threat modeling, static scanning, triage, execution-verified C/C++ memory-bug discovery, reporting, and patch generation. (Anthropic) — note: official reference implementation, not maintained as a product; the…;…

rust-in-peace

🟢 — Rust-security fork of Anthropic's defending-code reference harness, adding a Rust profile for agentic review of unsafe/FFI memory bugs, panic-DoS, deserialization-trust issues, and Miri/ASan/panic/hang-verified findings. (Sergey Gordeychik) — note: very new Apache-2.0 fork; autonomous runs…;…

claude-code-security-review

🟠 — Official Claude-based semantic SAST GitHub Action that reviews PR diffs. (Anthropic) · updated 2026-02-11)

In 2 lists

IRIS

🟢🔬 — Neurosymbolic SAST combining LLMs with CodeQL for Java vulnerability detection (MIT). · updated 2026-07-02)

sast-skills

🟢 — Agent skills that turn AI coding assistants into a multi-agent SAST scanner. · updated 2026-04-08); Related: Fraim · llm-sast-scanner

llm-sast-scanner

🟢 — SAST skill for AI coding agents with structured source-to-sink analysis across 34 vulnerability classes. License: MIT stated in README. · updated 2026-04-07); Related: sast-skills

sast-ai-workflow

🟢 — LangGraph workflow for reviewing static-analysis findings, reducing false positives, and producing vulnerability review output. (Red Hat Ecosystem AppEng) · updated 2026-06-29); Related: seclab-taskflow-agent · Fraim

llm-security-scanner

🟢⚠️ — LLM-powered code scanner that opens GitHub issues for findings. · updated 2025-04-02)

Trail of Bits Skills

🟢⚠️ — Claude Code- and Codex-compatible security workflow skills for code review, differential review, false-positive analysis, supply-chain checks, GitHub Actions auditing, Semgrep rule generation, and vulnerability research. (Trail of Bits) — note: reusable agent workflow instructions rather…;…

In 4 listsDetails

OpenHack

🟢 — File-based source-guided white-box security-review workspace that orchestrates agents through reconnaissance, vulnerability hunting, validation, evidence capture, and reporting. (Hadrian Security) — note: requires an external coding harness/model and can consume substantial model tokens;…;…

Buttercup

🟢🔬⚠️ — Multi-component cyber reasoning system for finding, validating, and patching software vulnerabilities with coordinated agent workflows. (Trail of Bits) — note: AGPL-3.0 research/competition system rather than a lightweight scanner; deployment uses multiple services, Docker, and…

AI-Powered Threat Modeling

tachi

🟢 — Threat modeling and AI-reasoning vulnerability detection harness for Claude Code that dispatches 14 specialized threat agents (6 STRIDE, 5 LLM, 3 agentic) against an architecture description in Mermaid, C4, PlantUML, ASCII, or free text, producing SARIF 2.1.0 for code scanning, MAESTRO…;…

STRIDE GPT

🟢 — LLM-powered threat modeling tool that generates STRIDE threat models, attack trees, data flow diagrams, DREAD risk scores, mitigations, and Gherkin test cases from application descriptions, architecture diagrams, or codebases (agentic analysis mode), with OWASP LLM Top 10 and Agentic (ASI)…;…

In 2 lists

LLM-Driven Fuzzing >Harness / target generation

oss-fuzz-gen

🟢 — LLM-driven fuzz-harness generation for OSS-Fuzz; reported 26 real vulnerabilities (incl. CVE-2024-9143 in OpenSSL). (Google) · updated 2026-03-02)

PromptFuzz

🟢🔬⚠️ — LLM-mutated prompts to generate fuzz drivers for C/C++ libraries (Rust). · updated 2026-05-15)

Fuzz4All

🟢🔬 — "Universal" LLM-based fuzzer across compilers/languages (ICSE 2024). · updated 2025-08-11)

ChatAFL

🟢🔬 — LLM-guided protocol fuzzing extending AFLNet (NDSS'24). · updated 2025-06-20)

In 2 lists

TitanFuzz

🟢🔬⚠️ — First LLM-based fuzzer for PyTorch/TensorFlow (ISSTA'23). · updated 2023-09-10)

LLM-Driven Fuzzing >Fuzzing the LLM

LLMFuzzer

🟢🔬 — First open-source fuzzing framework for LLM API integrations. — note: historical research reference; maintenance appears low compared with current LLM security scanners. · updated 2024-02-12)

In 3 lists

ps-fuzz

🟠 — System-prompt hardening fuzzer; 16 attacks × 16 providers. (Prompt Security) · updated 2026-02-16)

In 2 lists

FuzzyAI

🟠 — Automated LLM fuzzer for jailbreaks/prompt injection. (CyberArk) · updated 2026-02-06)

spikee

🟢 — Prompt-injection evaluation and exploitation kit with dataset generation, Burp integration, and pluggable judges. (ReversecLabs / WithSecure) · updated 2026-07-13); Related: promptmap

promptmap

🟢⚠️ — Prompt-injection scanner for custom LLM applications in white-box and black-box modes; GPL-3.0 licensed. · updated 2025-12-01); Related: spikee

In 2 lists

ai-prompt-fuzzer

🟢 — Burp Suite extension fuzzing GenAI/LLM prompts. (PortSwigger) · updated 2025-09-04)

Threat Intelligence

trs

🟢 — LLM + ChromaDB tool to summarize threat reports and extract MITRE TTPs and IOCs. · updated 2023-11-15)

TI-Mindmap-GPT

🟢 — Streamlit app: AI summaries, mindmaps, IOC/TTP extraction, and ATT&CK Navigator layers. · updated 2026-02-16)

aiocrioc

🟢 — LLM + OCR IOC extraction (pulls IOCs from images/PDFs). · updated 2024-12-04)

ThreatIngestor

🟢 — Extracts/aggregates IOCs from feeds; integrates with MISP/ThreatKB (pairs well with LLM post-processing). · updated 2026-05-26)

In 5 listsDetails

IATelligence

🟢 — Explains imported Windows APIs in PE files via GPT and maps to MITRE ATT&CK. · updated 2022-12-09); Related: MCP_Security

In 2 lists

MCP_Security

🟢⚠️ — MCP server (ORKL) for querying the ORKL threat-intel API. · updated 2025-01-22); Related: IATelligence

threat-intelligence-cti-analysis

🟢 — NLP/LLM pipeline for IOC extraction, MITRE ATT&CK mapping, and knowledge-graph generation from unstructured CTI. · updated 2025-11-03); Related: soctalk

CTINexus

🟢🔬 — LLM-assisted framework for data-efficient extraction of cyber-threat intelligence and construction of structured cybersecurity knowledge graphs from unstructured reports. — note: ships tests, releases, Docker configuration, and a Python package; extraction workflows require a configured…;…

CTIBench

🔬⚠️ — NeurIPS 2024 Spotlight benchmark with 4,610 examples across CTI knowledge, CWE root-cause mapping, CVSS prediction, ATT&CK technique extraction, and threat-actor attribution. — note: non-commercial research benchmark; the repository publishes data, evaluation notebooks, model outputs, and…;…

CTI-BERT

🟢🔬 — BERT model pretrained from scratch on a large cybersecurity text corpus for downstream CTI extraction, classification, and question-answering tasks. (IBM Research) license: Apache-2.0 · access: open · artifacts: PyTorch.

Log Analysis / SIEM / SOC Triage

AI-SOC-Agent

🟢 — Black Hat 2025 MCP server exposing security-investigation tools (ELK, IRIS). · updated 2025-12-28)

soctalk

🟢 — LangGraph SOC automation agent with MCP integrations for Wazuh, Cortex, TheHive, and MISP plus mock-agent test lab. · updated 2026-08-12); Related: SigmaOptimizer

In 2 lists

Vigil SOC

🟢 — Open-source AI SOC with readable Python agents, Markdown playbooks, and MCP integrations for triage, investigation, hunting, response, reporting, and forensics. (Vigil SOC) · updated 2026-08-17); Related: soctalk

agentic-soc-platform

🟢 — Agentic SOC platform (LangGraph/Dify) with local-LLM support. · updated 2026-08-05)

SigmAIQ

🟢⚠️ — pySigma wrapper and LangChain toolkit for automatic Sigma rule creation and translation; LGPL-2.1 licensed. (AttackIQ) · updated 2025-11-03); Related: SigmaOptimizer

RulePilot

🟢🔬 — LLM-powered security-rule generation agent for Splunk, Microsoft Sentinel, and Elastic, with field detection from log samples, multi-stage refinement, and cross-platform rule conversion. — note: MIT-licensed ICSE 2026 research prototype; requires an OpenAI API key. · updated 2025-10-20);…

SOCGPT

🟢 — LLM log summarization, severity triage, MITRE mapping, and Q&A. · updated 2025-06-11)

AttackGen

🟢 — LLM-driven incident-response scenario generator using MITRE ATT&CK + ATLAS. · updated 2026-08-13)

Google Security Operations and Threat Intelligence MCP Server

🟢 — MCP servers and packages that let MCP clients access Google Security Operations, SOAR, Google Threat Intelligence, and Security Command Center for investigation, hunting, and security automation workflows. (Google Cloud) — note: integration layer rather than an MCP-defense tool; requires…;…

ExCyTIn-Bench (SecRL)

🟢🔬 — ICML 2026 benchmark for evaluating LLM agents on cyber-threat investigation and threat hunting through security question-answering over eight anonymized incident databases. (Microsoft) — note: evaluation requires model-provider credentials, Dockerized MySQL incident databases, and roughly…;…

Reverse Engineering

DeepZero

🟢🔬 — Resumable Windows driver research framework combining Ghidra decompilation, static analysis, and optional LLM assessment through YAML pipelines. — note: the Windows-driver workflow requires an operator-provided Ghidra installation and optional LLM-provider credentials; analyze only drivers…

In 2 lists

Gepetto

🟢 — IDA Pro plugin: GPT adds comments and meaningful variable names. · updated 2026-08-15)

In 3 lists

ida-pro-mcp

🟢 — MCP bridge for IDA Pro exposing decompile, disassemble, xref, rename, and debugging workflows to LLM clients. · updated 2026-08-17)

In 3 lists

GhidraMCP

🟢 — MCP server exposing Ghidra reverse-engineering ops to any MCP-capable LLM. · updated 2025-06-23); Related: GhidrOllama · OGhidra

In 2 lists

ReVa

🟢 — Ghidra-focused reverse-engineering assistant with MCP support, Claude Skills integration, and long-form analysis workflows. · updated 2026-07-28); Related: GhidraMCP · GhidrAssistMCP

GhidrAssistMCP

🟢 — Native Ghidra MCP extension with broad tool coverage, headless support, and security-sensitive tool gating. · updated 2026-08-02); Related: ReVa · ghidra-mcp

ghidra-mcp

🟢 — Ghidra MCP server with large tool coverage, GUI plugin, headless server, and lazy tool loading. · updated 2026-08-12); Related: GhidrAssistMCP

In 2 lists

GhidrOllama

🟢⚠️ — Ghidra script using the Ollama API for function analysis/renaming. · updated 2024-11-29); Related: OGhidra · GhidraMCP

GhidraGPT

🟢 — Ghidra plugin that integrates LLMs for automated code refactoring and analysis. · updated 2026-07-22); Related: GhidraMCP · ReVa

LLM4Decompile

🟢🔬⚠️ — Research project for binary-to-C decompilation with LLMs; code is MIT, but model weights use a more restrictive license. · updated 2026-02-12)

x64dbg_mcp

🟢 — MCP server exposing x64dbg debugging and reverse-engineering operations to AI clients. · updated 2026-06-08)

In 2 lists

binaryninja-mcp

🟢 — MCP server for Binary Ninja-assisted reverse engineering. · updated 2025-05-13)

OGhidra

🟢 — Natural-language Ghidra analysis via Ollama. (Lawrence Livermore National Lab) · updated 2026-08-14); Related: GhidrOllama · GhidraMCP

ghidra_tools (G-3PO)

🟢 — Ghidra plugin for AI-assisted decompiled-code analysis. (Tenable) · updated 2023-05-10)

gpt-wpre

🔬 — Whole-program reverse engineering with GPT-3. · updated 2022-12-31)

In 3 lists

burpgpt

🟢 — Burp Suite extension integrating GPT for passive scanning. · updated 2024-06-09); Related: Burp-extension-for-GPT

In 3 lists

Burp-extension-for-GPT

🟢 — Burp extension to analyze HTTP traffic with GPT. (Tenable) · updated 2023-05-01); Related: burpgpt

REA

🟢 — Local CLI and MCP toolkit for agent-assisted reverse engineering of native binaries, managed PE/CLI files, JavaScript/Electron apps, and browser runtimes, using Hopper or an operator-provided Ghidra installation. — note: deep native analysis uses separately licensed Hopper or…; Related:…

In 2 lists

Open-ReverseLab

🟢⚠️ — Agent-native reverse-engineering workspace and MCP server combining Ghidra headless analysis with Frida, x64dbg, Rizin, YARA, and a runnable CTF/APK/PE knowledge base. — note: the repository additionally asserts a mandatory disclaimer with use, redistribution, derivative-work, and…;…

In 2 lists

LLM Red-Teaming & Guardrails >Scanners, Evals & Guardrails

RAMPART

🟢 — Pytest-native framework for repeatable adversarial and benign safety regression tests against AI agents, with statistical trials and evaluators for responses, tool calls, and external side effects. (Microsoft) — note: test framework built on PyRIT, not a runtime protection layer; users must…;…

In 2 lists

Agent OPFOR

🟢 — Adversary-emulation toolkit for AI agents, LLM applications, and MCP servers with multi-turn attack templates, tool and memory tests, trace-aware evaluation, CLI, SDK, browser, MCP, and skill interfaces. (KeyValue Software Systems) — note: attacker and judge workflows depend on configured LLM…

NuGuard

🟢 — Generates an AI-SBOM, statically analyzes agentic applications, red-teams live targets for prompt injection/tool misuse/data exfiltration, and validates behavioral policy compliance with SARIF, JSON, and Markdown reports. (NuGuard AI) — note: beta project; live red-team scans actively probe…;…

garak

🟢 — The LLM vulnerability scanner — probes for prompt injection, jailbreaks, data leakage, and more. (NVIDIA) · updated 2026-08-14); Related: PyRIT · promptfoo

In 4 listsDetails

PyRIT

🟢 — Python Risk Identification Tool; battle-tested across 100+ GenAI red-team operations. (Microsoft) · updated 2026-08-14)

In 2 lists

promptfoo

🟢 — LLM eval + red-teaming/pentesting CLI with 50+ attack plugins (MIT). Note: OpenAI announced an acquisition agreement in March 2026; remains MIT-licensed — track governance. · updated 2026-08-17)

In 11 listsDetails

Augustus

🟢 — Single-binary LLM security testing framework for prompt injection, jailbreaks, and adversarial attacks across many providers. (Praetorian) · updated 2026-08-17); Related: garak · PyRIT

agentic_security

🟢 — Agentic LLM vulnerability scanner and AI red-team kit for jailbreaks, prompt injection, fuzzing, and API stress testing. · updated 2026-07-31); Related: garak · spikee

In 3 lists

HackAgent

🟢 — Python SDK and CLI for red-teaming AI agents with research-backed attacks such as AdvPrefix, AutoDAN-Turbo, PAIR, TAP, FlipAttack, BoN, and static templates across agent frameworks. — note: works locally without an API key; optional cloud reporting is available. · updated 2026-08-15);…

wallbreaker

🟢🔬⚠️ — Claude-Code-style terminal and red-team harness for authorized LLM safety testing, with HarmBench, PAIR/TAP, Crescendo, GCG-style workflows, Parseltongue transforms, MCP tooling, LLM judges, and reproducible run artifacts. — note: offensive jailbreak toolkit for authorized testing only;…;…

HiveTrace Red

🟢 — Early-stage LLM red-teaming framework with 80+ attack templates, async evaluation pipelines, WildGuard evaluators, multi-provider support, and HTML reporting. — note: young project with limited independent adoption signal. · updated 2026-08-13); Related: garak · PyRIT · promptfoo

DeepTeam

🟢 — Open-source framework for red-teaming LLMs and LLM systems across jailbreaks, prompt injection, data leakage, and safety risks. · updated 2026-08-12)

In 3 lists

Moonshot

🟢 — Modular tool for benchmarking, red-teaming, and evaluating LLM applications with custom connectors and recipes. (AI Verify Foundation) · updated 2026-02-05)

Guardrails AI

🟢 — Python framework for adding input/output guards, validators, structured-output controls, and Guardrails Hub checks to LLM applications. (Guardrails AI) · updated 2026-08-14); Related: NeMo Guardrails · LLM Guard

In 6 listsDetails

Giskard

🟢 — Open-source evaluation, testing, and red-teaming framework for LLM agents, including agent vulnerability scanning and RAG evaluation workflows. (Giskard AI) · updated 2026-08-17); Related: Moonshot · promptfoo

In 3 lists

LangKit

🟢 — LLM monitoring toolkit extracting safety/security signals such as jailbreak similarity, prompt-injection similarity, hallucination checks, PII patterns, toxicity, and refusal metrics. (WhyLabs) · updated 2024-11-22)

In 4 listsDetails

LLM Guard

🟢 — Suite of input/output scanners (PII, prompt injection, etc.). (Protect AI) — note: archived by the maintainer; retained as a historical reference for local input/output guardrails. · updated 2026-07-08); Related: Rebuff

In 3 lists

Rebuff

🟢 — Archived prompt-injection detector (heuristics + LLM + vector DB + canary tokens). (Protect AI) — note: archived by the maintainer; retained as a historical prompt-injection defense reference. · updated 2024-01-25); Related: LLM Guard

In 4 listsDetails

NeMo Guardrails

🟢 — Programmable guardrails (input/output/dialog/retrieval rails) for LLM apps. (NVIDIA) · updated 2026-08-17)

In 6 listsDetails

PurpleLlama

🟢 — Llama Guard classifiers, CodeShield, and CyberSecEval. (Meta) · updated 2026-08-14)

In 3 lists

LLAMATOR

🟢⚠️ — Red-teaming framework for chatbots and GenAI systems; CC BY-NC-SA 4.0 licensed. · updated 2026-01-15)

Vigil

🟢🔬 — Library/REST API to scan prompts and responses for prompt injection. · updated 2024-01-31)

In 2 lists

Counterfit

🟢 — ML/AI penetration-testing automation tool. (Microsoft) · updated 2025-07-18)

In 2 lists

AI-Red-Teaming-Playground-Labs

🟢 — CTFd-based AI red-team training challenges. (Microsoft) · updated 2025-10-07)

EasyJailbreak

🟢🔬 — Framework for building and testing adversarial jailbreak prompts. · updated 2026-03-30)

TextAttack

🟢🔬 — Python framework for adversarial attacks, data augmentation, and training for NLP models; useful for robustness testing beyond chat-only LLM scanners. · updated 2026-08-15)

In 6 listsDetails

GPTFuzz

🟢🔬 — Research framework for red-teaming LLMs with auto-generated jailbreak prompts. · updated 2026-02-27)

HarmBench

🟢🔬 — ICML 2024 standardized evaluation framework for automated red-teaming and robust-refusal benchmarking. (Center for AI Safety) · updated 2024-08-05); Related: JailbreakBench

llm-attacks (GCG)

🟢🔬 — Canonical Greedy Coordinate Gradient adversarial-suffix attack implementation for transferable attacks on aligned language models. · updated 2024-08-02); Related: nanoGCG

nanoGCG

🟢 — Fast, lightweight PyTorch implementation of the GCG adversarial-suffix algorithm. · updated 2025-05-13); Related: llm-attacks (GCG)

JailbreakBench

🟢🔬 — NeurIPS 2024 open robustness benchmark and leaderboard for generating and defending against LLM jailbreaks. · updated 2025-03-31)

Open-Prompt-Injection

🟢🔬 — Open-source toolkit and benchmark for implementing and evaluating prompt-injection attacks, defenses, and LLM-integrated applications. · updated 2025-10-29)

In 2 lists

PINT Benchmark

🟢🔬 — Prompt-injection test benchmark for evaluating detectors and guardrails across multilingual prompt injection, jailbreak, benign, and hard-negative inputs. (Lakera) — note: archived benchmark retained as a historical research reference; use newer maintained corpora for current detector…;…

PIArena

🟢🔬 — ACL 2026 toolbox and benchmark for prompt-injection attacks and defenses, with ready-to-use attacks/defenses, evaluation pipelines, agent benchmarks, a Hugging Face dataset, and leaderboard. · updated 2026-04-20); Related: PINT Benchmark · Open-Prompt-Injection

Whistleblower

🟢⚠️ — Offensive testing tool for inferring system prompts and discovering capabilities of LLM applications exposed through APIs. (Repello AI) — note: no LICENSE file found. · updated 2025-10-27)

In 2 lists

LLMmap

🟢🔬 — Minimal-query fingerprinting tool for identifying LLMs from behavioral traces, with a pretrained open-set inference model. · updated 2025-07-24)

llm-security

🔬 — Original PoC for indirect prompt-injection attacks. · updated 2025-07-17)

In 2 lists

JailbreakLLMs

🔬⚠️ — Research dataset of 6,387 ChatGPT prompts, including in-the-wild jailbreak prompts from Reddit, Discord, websites, and open datasets. · updated 2024-02-21)

Do-Not-Answer

🟢🔬 — Dataset for evaluating LLM safeguards on unsafe or policy-sensitive prompts. · updated 2024-06-07)

prompt-injection-defenses

🟢⚠️ — Curated catalog of practical defenses against prompt injection. · updated 2025-02-22)

In 2 lists

little-canary

🟢🔬 — Prompt-injection preflight sensor that probes untrusted input with a powerless canary model and returns PASS, FLAG, or BLOCK with explicit coverage state before primary-agent action; includes opt-in Claude Code prompt-submission and OpenAI Agents SDK input-boundary adapters. — note:…;…

Kiji Privacy Proxy

🟢 — Local privacy proxy for OpenAI-compatible AI API traffic that detects and masks 26 PII types with an ONNX model before forwarding requests, then restores mappings in responses. (Dataiku 575 Lab) — note: protects configured proxied traffic, not every path by which an application or agent can…;…

Anamorpher

🟢🔬 — Research tool with a frontend and Python API for crafting and visualizing image-scaling attacks that reveal hidden prompt injections to multimodal AI systems after downscaling. (Trail of Bits) — note: active beta research tool for authorized testing; generated payloads are sensitive to…

Prompt SIREN

🟢🔬 — Research workbench for developing and evaluating prompt-injection attacks and defenses with state-machine agent control, AgentDojo/SWE-bench integrations, configuration sweeps, and reproducible result aggregation. (Meta AI) — note: experiment harness; running target evaluations requires…;…

Argus

🟢🔬 — Black-box red-team framework for LLM applications and agents with target adapters, attack probes, deterministic and model-assisted judging, and SARIF, JUnit, HTML, and JSON reporting. — note: pre-1.0 project; full deployments use an orchestrator and PostgreSQL, while model-assisted judges…;…

Cryptex OSS

🟢🟠 — Browser-based and self-hostable adversarial prompt workbench with transformation pipelines, campaign workflows, TAP/PAIR/Crescendo methods, and HarmBench/JailbreakBench-style corpora. — note: authorized-testing toolkit; provider keys are supplied by the operator and retained in browser…;…

API Relay Audit

🟢⚠️ — Local audit CLI for third-party LLM relays and proxies, testing prompt injection, model substitution, tool-call rewriting, streaming behavior, and relay-specific trust assumptions. — note: sends the supplied API credential to the relay being tested, so use a scoped disposable key and only…;…

AIDR Bastion

🟢🟠⚠️ — Runtime input-protection service combining detection rules, similarity search, classifiers, optional LLM analysis, and code-oriented checks to allow, block, or notify on suspicious GenAI traffic. (SOC Prime) — note: multi-service deployment can require OpenSearch/Elasticsearch, Qdrant,…;…

CaMeL

🟢🔬 — Research implementation of the capability-based CaMeL interpreter architecture for separating trusted control flow from untrusted data while evaluating prompt-injection defenses on AgentDojo. (Google Research / Google DeepMind / ETH Zurich) — note: unsupported paper-reproduction artifact…;…

Meta SecAlign

🔬⚠️ — Research code, training recipe, and evaluation harness for prompt-injection-resistant Meta SecAlign models across six security and eight utility benchmarks. (Meta / UC Berkeley) — note: most repository code is non-commercial while published model weights use separate Llama community…

LLM Red-Teaming & Guardrails >Prompt-Injection Classifier Models

Wolf Defender Prompt Injection

🟢 — Hugging Face text-classification model for prompt-injection detection in agents, chatbots, and CI workflows. (Patronus Studio / Casdo Labs) license: Apache-2.0 · access: open · artifacts: Safetensors, ONNX.

DeBERTa v3 Prompt Injection v2

🟢 — Apache-licensed prompt-injection classifier usable via Transformers pipelines and ONNX. (Protect AI) license: Apache-2.0 · access: open · artifacts: Safetensors, ONNX.

PromptGuard

🟢⚠️ — ModernBERT-based prompt-injection and jailbreak classifier. (CodeIntegrity AI) license: Apache-2.0 · access: gated auto · artifacts: Safetensors.

Prompt Guard 86M

🟠⚠️ — Meta prompt-injection and jailbreak classifier from the Llama Guard family. (Meta) license: Llama 3.1 · access: gated manual · artifacts: Safetensors.

prompt-injection-sentinel

🔬⚠️ — ModernBERT-large classifier for prompt-injection and jailbreak detection. (Qualifire) license: other · access: gated auto · artifacts: Safetensors.

LLM Red-Teaming & Guardrails >Specialty Security LLMs

SecGPT

🟢 — Open cybersecurity-tuned LLM family for vulnerability analysis, log/traffic investigation, anomaly detection, attack/defense reasoning, command analysis, and security Q&A. (Clouditera) · updated 2025-06-25); Related: SecGPT model

In 2 lists

Antares-1B

🟢⚠️ — Open-weight security SLM specialized for agentic vulnerability localization: it explores repository snapshots through a terminal-style loop and ranks likely vulnerable files for analyst review. (Cisco Foundation AI) license: Apache-2.0 · access: gated manual · artifacts: Safetensors + CLI…

Trendyol Cybersecurity LLM v2 70B

🟢 — Defense-focused cybersecurity LLM based on Llama-3.3-70B, trained on an alignment-safe security instruction dataset for SOC, cloud, AppSec, detection, and vulnerability-management workflows. (Trendyol Group Security Team) license: Apache-2.0 · access: open · artifacts: GGUF.

WhiteRabbitNeo 2.5 Qwen Coder 7B

🟢⚠️ — Cybersecurity-oriented Qwen2.5-Coder fine-tune positioned for offensive and defensive security assistance. (WhiteRabbitNeo) license: Apache-2.0 + WhiteRabbitNeo restrictions · access: open · artifacts: Safetensors.

Lily-Cybersecurity-7B-v0.2

🟢 — Mistral-7B-Instruct fine-tune for cybersecurity assistance, trained on hand-crafted security and hacking-related instruction pairs. (Segolily Labs) license: Apache-2.0 · access: open · artifacts: Safetensors.

RavenX CyberAgent 35B Q4_K_M

🟢⚠️ — GGUF security-specialized text-generation model positioned for pentest, bug-bounty, tool-calling, MCP, CVSS/CWE, and MITRE ATT&CK workflows. (RavenX LLC / DeadByDawn101) license: Apache-2.0 · access: open · artifacts: GGUF. — note: built from an abliterated base model and marketed for…

LLM Honeypots & Deception

Beelzebub

🟢⚠️ — Low-code honeypot using LLMs to simulate SSH/HTTP/MCP services (Go). — note: GPL-3.0 licensed. · updated 2026-08-11)

DECEIVE

🟢🔬 — Proof-of-concept LLM-powered SSH honeypot that evaluates sessions as benign, suspicious, or malicious. (Splunk) · updated 2026-05-13)

TRAP

🟢🔬 — Research code for Targeted Random Adversarial Prompt honeypots that identify black-box LLM usage through model-specific prompt suffixes (ACL 2024 Findings). · updated 2024-11-20)

shelLM

🟢🔬 — LLM-powered SSH honeypot (paper "LLM in the Shell"). · updated 2026-06-25); Related: VelLMes

VelLMes

🟢🔬 — Multi-protocol LLM honeypot framework (successor to shelLM). · updated 2025-02-18); Related: shelLM

llm-honeypot

🔬⚠️ — Cowrie SSH honeypot extended with prompt-injection traps to detect LLM hacker agents. (Palisade Research) · updated 2026-01-23)

CTF / Exploit / Bug-Bounty Agents & Benchmarks

Inspect Cyber

🟢🔬 — Installable Inspect extension for defining and running agentic cyber evaluations with standardized YAML configurations, adaptable sandboxes, scenario variants, scoring, and solvability verification. (UK AI Security Institute) — note: evaluation framework rather than a benchmark result or…;…

GenAI Red Team Lab

🟢🔬 — Collection of intentionally vulnerable GenAI sandboxes, exploitation examples, and tutorials for prompt injection, memory poisoning, orchestration attacks, guardrail bypass, and related red-team exercises. (OWASP GenAI Security Project) — note: training and research lab, not a scanner; it…

SWE-agent (EnIGMA)

🟢🔬 — EnIGMA offensive-CTF mode; SOTA on NYU CTF, InterCode-CTF, and Cybench (v0.7 branch). · updated 2026-07-16); Related: Cybench · NYU CTF Bench · InterCode

In 4 listsDetails

Cybench

🔬 — 40 professional CTF tasks across 4 competitions; widely used by AI safety institutes. · updated 2026-07-09)

NYU CTF Bench

🔬 — Dockerized CSAW CTF challenges for LLM-agent evaluation. · updated 2025-09-22)

CTFTiny

🔬⚠️ — Lightweight CTF benchmark from the NYU LLM CTF group; GPL-2.0 licensed. · updated 2026-03-10); Related: NYU CTF Bench

InterCode

🔬 — Interactive-coding benchmark incl. InterCode-CTF. · updated 2024-05-05)

inspect_evals

🟢🔬 — Maintained Inspect AI evaluation suite containing multiple cyber benchmarks and tasks. (UK AI Security Institute) · updated 2026-08-17)

BountyBench

🔬 — 25 real systems / 40 bug bounties for Detect-Exploit-Patch evaluation. · updated 2025-06-22)

Cyber-Zero

🔬 — Trains cybersecurity agents without runtime; ships an EnIGMA+ scaffold. (Amazon Science) — note: archived research artifact retained as a historical reference for training cybersecurity agents without a live runtime. · updated 2025-09-02); Sources: SWE-agent; Related: SWE-agent

ExploitBench

🔬 — Measures AI-agent progress on V8/Chromium exploit ladders. · updated 2026-07-04)

AI Goat

🟢🔬⚠️ — Vulnerable-by-design local LLM CTF for learning prompt injection, insecure output handling, data leakage, excessive agency, and related LLM app risks. — note: GPL-2.0 licensed. · updated 2024-08-22)

AIGoat

🟢🔬⚠️ — Local-first vulnerable LLM security playground with guided OWASP LLM Top 10 attack labs, CTF challenges, progressive defenses, and an Ollama-backed AI shopping-assistant target. — note: platform code is Apache-2.0, but training/challenge content is CC BY-NC-SA-4.0 and requires permission…

LLMVault

🟢🔬 — Intentionally vulnerable LLM security-training platform with OWASP LLM Top 10 labs, CTF-style challenges, hints, scoring, and mitigation guidance. — note: deliberately vulnerable training target; run only in an isolated, authorized environment. Live Mode optionally requires Ollama or…

In 2 lists

Damn Vulnerable LLM Agent

🟢🔬 — Deliberately vulnerable LangChain ReAct agent for practicing prompt-injection and Thought/Action/Observation injection attacks. (ReversecLabs / WithSecure) · updated 2025-06-25); Related: spikee

claude-bug-bounty

🟢 — Claude Code plugin orchestrating recon → vuln classes → reporting. · updated 2026-08-10)

Bug-Bounty-Agents

🟢 — 43 AI agent personas for Claude Code / Copilot / Cursor across the bug-bounty lifecycle. · updated 2026-04-30)

ai-exploits

🟢 — Real-world AI/ML exploits (Metasploit modules + Nuclei templates) for MLflow, Ray, H2O. (Protect AI) · updated 2024-10-23)

In 2 lists

CyberGym

🟢🔬 — Large-scale evaluation framework for AI-agent vulnerability analysis on real-world tasks, with locally deployed challenge infrastructure, task generation, and proof-of-concept validation. (UC Berkeley / Sunblaze) — note: deploy only in an isolated local environment; the full benchmark…;…

CVE-Bench

🟢🔬 — ICML 2025 benchmark that evaluates AI agents against reproducible Docker environments for real critical-severity web-application CVEs and exploit objectives. — note: runs intentionally vulnerable services and should be used only in isolated environments; arm64 support is experimental. ·…;…

SCAM

🟢🔬 — Benchmark for measuring whether tool-using agents recognize and resist realistic scams, social engineering, credential requests, impersonation, and unsafe multi-turn instructions across 30 scenarios and nine threat categories. (1Password) — note: evaluation requires at least one…

AIRTBench-Code

🟢🔬 — Research harness and dataset for evaluating autonomous AI red-team agents on AI/ML security CTF challenges, with published task definitions and result artifacts. (Dreadnode) — note: the public code and dataset accompany arXiv 2506.14682, but reproducing the full evaluation depends on…;…

AI-Goat (Orca Security)

🟢🔬 — Deliberately vulnerable AWS and Terraform lab for learning AI/ML infrastructure risks such as model supply-chain compromise, data poisoning, insecure output handling, and integrity failures. (Orca Security Research) — note: distinct from the local LLM playgrounds with similar names;…

LivePI

🔬⚠️ — Reproducibility artifact for a production-like indirect prompt-injection benchmark spanning live but test-controlled email, chat, web, local-file, repository, and wallet surfaces. — note: benchmark setup interacts with live test accounts and services and includes attack scenarios capable…

Cloud / IaC / DFIR / OSINT / Phishing

EscalateGPT

🟢 — GPT-based discovery of privilege-escalation paths in AWS IAM policies. (Tenable) · updated 2024-01-17)

Cynative

🟢 — Local AI security research agent for cloud, code, and runtime environments across GitHub, GitLab, AWS, GCP, Azure, and Kubernetes, with read-only action gates, sandboxed code execution, evidence-backed verification, and audit logs. · updated 2026-08-14); Related: Fraim · EscalateGPT

In 6 listsDetails

Julius

🟢 — Local Go tool that fingerprints LLM service infrastructure on authorized endpoints, identifies 60+ serving, gateway, MCP, and RAG platforms, and can enumerate exposed models. (Praetorian) — note: use only against endpoints you own or are authorized to assess. · updated 2026-08-06); Related:…

MemoryInvestigator

🔬 — Volatility 3 + LLM + RAG for memory-forensic triage. · updated 2025-09-16); Related: Volatility-MCP-Server

Volatility-MCP-Server

🟢 — MCP exposing Volatility 3 plugins for natural-language memory forensics. · updated 2025-07-07); Related: MemoryInvestigator

llm_osint

🟢🔬 — Proof-of-concept LLM OSINT framework using knowledge and web agents for internet research workflows. · updated 2024-11-02)

ai_osint

🟢 — Curated AI-OSINT dorks, queries, and techniques for discovering exposed LLM and AI infrastructure. · updated 2026-06-19)

PhishLLM

🔬⚠️ — Reference-less phishing detection via LLM brand recognition (USENIX'24). · updated 2026-06-04); Related: PhishVLM

mcp-dnstwist

🟢 — MCP server for dnstwist DNS fuzzing to support typosquatting, phishing, and lookalike-domain analysis. · updated 2025-03-03)

osintgpt

🟢⚠️ — OpenAI embeddings + Qdrant over OSINT corpora. · updated 2023-12-11)

See category
94

Table of Contents

hesreallyhim/awesome-claude-code

A hand-picked collection of the finest of resources for the most awesome of agents, Claude Code, the undisputed champion of coding companions, from the unstoppable team…

Fresh★ 55k202 entriesPushed today
94

Awesome Agent Skills

VoltAgent/awesome-agent-skills

A curated collection of 1000+ agent skills from official dev teams and the community, compatible with Claude Code, Codex, Gemini CLI, Cursor, and more.

Fresh★ 35k839 entriesPushed today
93

Awesome Machine Learning

josephmisiti/awesome-machine-learning

A curated list of awesome Machine Learning frameworks, libraries and software.

Fresh★ 74k1188 entriesPushed 7 days ago
92

Awesome Production Machine Learning

EthicalML/awesome-production-machine-learning

A curated list of awesome open source libraries to deploy, monitor, version and scale your machine learning

Fresh★ 21k519 entriesPushed 3 days ago
92

AWESOME DATA SCIENCE

academic/awesome-datascience

:memo: An awesome Data Science repository to learn and apply for real world problems.

Fresh★ 30k881 entriesPushed today
91

Static Analysis

analysis-tools-dev/static-analysis

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve…

Fresh★ 15k528 entriesPushed 8 days ago