Awesome AI Security Tools
A curated list of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity — autotriage, agent security, AI/ML supply chain, pentest agents, AI SAST, LLM-driven fuzzing, threat intelligence, SOC/SIEM triage, reverse engineering, LLM red-teaming, and more.
nuclei-autotriage🟢⚠️ — Two-stage LLM triage (falsifier + red-team pass) of Nuclei JSONL findings via OpenAI-compatible endpoints…
seclab-taskflow-agent🟢 — YAML-driven taskflow agent framework for triaging CodeQL/SAST alerts and filtering false positives. (GitHub…
honeyslop🟢 — Code-canary decoys to triage AI-hallucinated ("slop") vulnerability reports flooding bug-bounty programs. ·…
nano-analyzer🟢🔬 — Minimal three-stage LLM pipeline (context → scan → skeptical triage) for zero-day discovery in C/C++. (AISLE) ·…
SigmaOptimizer🟢 — Generates, tests, and refines Sigma rules from real logs with false-positive checking. · updated 2025-08-01);…
ai-soc-triage-assistant🟢⚠️ — SOC alert triage assistant with prompt-injection guardrails, output validation, and MITRE ATT&CK mapping. ·…
agent-audit🟢 — Forensic auditor for local AI coding agents (Claude Code, Codex CLI, OpenClaw) and project-surface scanner for…
AI-Infra-Guard🟢 — Full-stack AI red-teaming platform covering OpenClaw security scan, agent scan, skills scan, MCP scan, AI-infra…
SkillSpector🟢 — Security scanner for AI-agent skills used by Claude Code, Codex CLI, Gemini CLI, and similar ecosystems; combines…
Ramparts🟢 — Rust scanner for MCP servers and agent-skill bundles with YARA rules, optional LLM analysis, OSV/CVE lookups,…
mcp-armor🟢 — Local MCP security scanner with auto-discovery for agentic IDE configs, tool/resource/prompt inventory,…
aguara🟢 — Single-binary static scanner (Go, no LLM) for AI-agent skills and MCP servers; multi-layer engine (pattern + NLP…
agent-scan🟢 — Security scanner for AI agents, MCP servers, and agent skills; the successor path for the original Invariant Labs…
inkog🟠 — Commercial-backed static security scanner for AI agents across LangChain, LangGraph, CrewAI, AutoGen, and no-code…
AgentShield🟢 — Security scanner for AI-agent configurations, MCP servers, hooks, and tool permissions with CLI, GitHub Action,…
repo-forensics🟢⚠️ — Offline scanner for AI-agent repos, skills, plugins, and MCP servers; license is PolyForm Noncommercial. ·…
skill-scanner🟠 — Scanner for agent skills combining YAML + YARA patterns, LLM-as-a-judge, and behavioral dataflow analysis (Codex…
mcp-scanner🟢⚠️ — Scanner for MCP servers and agentic tool surfaces, covering tools, prompts, resources, package risk, malware…
mcp-guardian🟢 — JS/TS library and CLI for detecting prompt injection in MCP tool descriptions and pinning tool definitions. ·…
MCP Observatory🟢🟠 — CI-native MCP-server testing tool for schema drift, safe attack simulation, record/replay verification, health…
agentic-radar🟠 — CLI security scanner for agentic workflows (LangGraph, CrewAI, n8n, etc.) — maps tools/data flows and flags…
skilltotal🟢 — Offline deterministic static scanner (regex + AST, no LLM, no account) for AI components — agent skills/plugins,…
Sunglasses🟢 — Local input/content scanner for AI agents that checks prompts, files, media metadata, skills, and tool…
trentclaw🟠 — Client-side security auditor for OpenClaw deployments: applies pattern-based secret redaction locally, then…
A2A Security Scanner🟢 — CLI and PyPI scanner for Agent-to-Agent (A2A) agent cards, source code, registries, and live endpoints using…
Ship Safe🟢🟠 — Local security CLI for application code, AI-agent and MCP configuration, secrets, dependencies, CI, and…
AgentSeal🟠⚠️ — Agent-security CLI and runtime library for scanning MCP servers, skills, prompts, and configuration, plus local…
SlowMist Agent Security🟢 — Security-review skill and workflow for auditing agent skills, MCP servers, repositories, URLs, and documents…
Sandbox Probe🟢 — Static Go probe that measures the effective filesystem, network, process, credential, and runtime capabilities…
Project CodeGuard🟢⚠️ — Model-agnostic secure-coding rules and skills framework with translators for popular coding agents, validators,…
asamm🔬 — Agentic SAMM — an OWASP SAMM extension for AI-driven development: an entry-point-based threat taxonomy plus 17…
agent-threat-rules (ATR)🟢 — Open, versioned, machine-readable detection rules for AI-agent threats (prompt injection, tool poisoning, MCP…
Agent Governance Toolkit🟢 — Multi-language toolkit for policy-enforced agent tool calls and audit records, with optional identity,…
MCP-Security-Checklist🟢 — Security checklist for MCP clients, servers, multi-MCP deployments, lifecycle controls, authz/authn, isolation,…
Anthropic-Cybersecurity-Skills🟢 — Large community cybersecurity skill library for AI agents, mapped to MITRE ATT&CK, NIST CSF, MITRE ATLAS, D3FEND,…
Claude-BugHunter🟢 — Claude Code / agent-skill bundle for authorized bug hunting and external red-team workflows across web, API,…
AgentDojo🟢🔬 — Benchmark environment for prompt-injection attacks and defenses in tool-using LLM agents. · updated…
Agent3Sigma-Canary🟢🔬 — Sandboxed research framework for evaluating AI-agent security over complete execution trajectories, covering…
Agent Security Bench (ASB)🟢🔬 — Official ICLR 2025 benchmark for evaluating attacks and defenses in LLM-based agents across ten scenarios,…
Skill-Inject🟢🔬 — Benchmark for measuring prompt-injection vulnerabilities carried by agent skill files across Claude Code, Codex…
AI Security Verification Standard (AISVS)🔬⚠️ — Stable verification standard defining testable security requirements for AI applications across model…
OWASP Agent Security Regression Harness🟢 — Vendor-neutral harness for running repeatable agent and MCP abuse scenarios, evaluating policy assertions over…
OpenShell🟢 — Policy-governed runtime for autonomous and coding agents with container or microVM-backed sandboxes,…
Numbat🟢 — Endpoint-local visibility and detection for AI-agent activity across hooks, plugins, OTLP, and on-disk artifacts,…
agentsh🟢 — Execution-layer policy shell for AI agents that intercepts file, network, process, signal, and selected database…
brood-box🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots,…
Greywall🟢 — Kernel-enforced filesystem, network, syscall, and command-policy wrapper for coding agents on Linux and macOS,…
nono🟢 — Least-privilege sandbox for AI coding agents that isolates the agent and delegated tools with composable…
cplt🟢 — Kernel-backed sandbox wrapper for AI coding agents that applies Seatbelt on macOS or Landlock and seccomp on…
Arcjet Guard🟢🟠 — JavaScript runtime guard for AI-agent tool calls and MCP handlers, with prompt-injection detection,…
ToolHive🟢 — Platform for running MCP servers in isolated containers with per-request identity/access policy, registry and…
Pipelock🟢 — AI-agent firewall and verifiable egress-control layer mediating HTTP, WebSocket, CONNECT, MCP, and A2A traffic to…
node9🟢 — Local policy and human-approval gate for supported coding-agent tool calls routed through agent hooks or an MCP…
SourceryKit🟠⚠️ — Python SDK for agent guardrails that intercepts outbound HTTP calls, enforces trusted-endpoint policies, logs…
emisar🟠⚠️ — Agent-infrastructure control plane that exposes declared, typed actions through MCP, applies policy and…
mcp-context-protector🟢 — MCP security wrapper that sits in front of downstream MCP servers, scans tool responses with guardrail providers,…
MCP Defender🟢⚠️ — Desktop app that proxies MCP tool-call requests and responses for Cursor, Claude, VS Code, and Windsurf, checks…
MCP Gateway🟢 — Plugin-based MCP gateway that proxies configured MCP servers, sanitizes sensitive request/response data, supports…
Parallax🟢 — Rust runtime policy engine for AI agents: evaluates lifecycle events with regex, keyword, Sigma, CEL, and SQL…
Armorer Guard🟢 — Local Rust scanner and MCP proxy for AI-agent prompt injection, credential leakage, exfiltration, and risky…
onecli🟢 — Credential gateway and encrypted vault for AI agents; injects real API credentials at the gateway so agents only…
microsandbox🟢 — Local-first, microVM-backed programmable sandboxes for AI agents with SDKs, CLI, MCP support, and rootless…
agentguard🟢 — Real-time security layer for coding agents: hooks scan every new skill, block dangerous actions before execution,…
defenseclaw🟠 — Enforcement and evidence layer for agentic deployments: static CodeGuard checks, sandboxing, registry ingestion…
clawsec🟢⚠️ — Security skill suite for OpenClaw-family agents; AGPL-3.0 licensed. (Prompt Security) · updated 2026-08-05);…
AgentLock🟢🔬⚠️ — Pre-action authorization gate for LLM agent tool calls that decides from session provenance rather than…
h5i🟢 — Local Rust CLI for auditable coding-agent workspaces: per-agent worktrees with sandbox policies, provenance…
DvalinCode🟢 — Local-first AI coding agent with runtime governance controls: org/repo policy gates for tools, models, MCP…
TAP🟢🟠 — Credential-isolation proxy and MCP server for AI agents: agents send placeholder credentials, TAP injects real…
Agent Memory Guard🟢 — Runtime middleware for AI-agent memory reads and writes, screening prompt injection, memory poisoning, secret/PII…
AIO Sandbox🟢⚠️ — All-in-one Docker workspace for AI agents with browser, shell, file, code-execution, MCP, and VSCode…
Agentgateway🟢 — Agent-native proxy and gateway for MCP and A2A traffic with OAuth/JWT/API-key authentication, CEL-based RBAC…
Kubernetes Agent Sandbox🟢 — Kubernetes CRDs and controllers for isolated, stateful singleton agent workloads, delegating low-level isolation…
Prismor🟢 — Self-hosted runtime control plane for coding agents with pre-tool-call hooks, policy-driven observe/approve/block…
Gram🟢🟠⚠️ — Open-source stack behind Speakeasy's AI control plane that centrally manages MCPs, Skills, and Assistants…
tirith🟢⚠️ — Terminal guard for developers and AI coding agents that intercepts homograph and terminal-injection tricks,…
ADR🟢🔬 — Agentic AI Detection and Response system combining cross-client agent telemetry, ADR-Bench security scenarios,…
xaidr🟢 — In-process runtime security sensor for AI agents that inspects input, tool calls, output, and agent-to-agent…
Agentmetry🟢 — Local-first flight recorder for AI coding agents and MCP servers that writes a hash-chained JSONL trail with RFC…
piighost🟢 — Local runtime pseudonymization layer that replaces detected PII with stable placeholders before model calls and…
HOL Guard🟢🟠 — Local-first runtime security layer for coding agents that evaluates commands, package installs, skills, MCP…
StackOne Defender🟢 — Offline TypeScript runtime guard for indirect prompt injection in tool results, using bundled ONNX classifiers,…
Earl🟢 — Capability proxy for AI agents that exposes approved operation names while keeping request templates and…
Bifrost🟢🟠 — Apache-licensed AI and MCP gateway with multi-provider routing, virtual-key access controls, budgets, rate…
Portkey AI Gateway🟢🟠 — Open AI gateway with provider routing, fallback and retry controls, guardrail integrations, observability, and…
Casbin AI Gateway🟢 — Local gateway and policy layer for model-provider and MCP traffic, combining provider-key mediation, access…
Adrian🟢🟠 — Runtime monitoring and intervention layer that correlates agent actions with available reasoning traces through…
Sandlock🟢 — Unprivileged Linux process sandbox using Landlock, seccomp-BPF, and seccomp user notification to apply…
Lunar🟢🟠 — API and MCP gateway combining outbound-traffic visibility, policy enforcement, rate limits, retries, circuit…
Norviq🟢 — Kubernetes policy enforcement point for LLM agent tool calls that content-hash pins each tool definition at…
sofagent🟢 — Commit-time audit and governance suite for AI coding agents that scans git diffs against deterministic rules,…
AI BOM🟢 — Inventories models, agents, tools, MCP clients and servers, datasets, prompts, guardrails, secrets, and cloud AI…
Fraim🟢 — Framework for AI-powered security workflows including LLM SAST and IaC analysis with SARIF/HTML output. · updated…
Adversarial Robustness Toolbox (ART)🟢 — Flagship machine-learning security library for evaluating and defending models against evasion, poisoning,…
Foolbox🟢 — Classic Python toolbox for generating adversarial examples and benchmarking robustness of PyTorch, TensorFlow,…
modelscan🟢 — Scans ML model files for unsafe serialization patterns and embedded code, with a focus on model serialization…
Fickling🟢 — Python pickle decompiler, rewriter, and static analyzer for inspecting and detecting malicious pickle/PyTorch…
picklescan🟢 — Lightweight CLI/library for detecting suspicious Python pickle operations in ML and model artifacts. · updated…
AIsbom🟢 — AI software bill of materials tooling for AI/ML supply-chain inventory and provenance metadata. · updated…
model-provenance-kit🟢 — Toolkit for model-family provenance and fingerprinting across model weights, tokenizers, and architecture…
pickle-fuzzer🟢 — Structure-aware fuzzer for pickle scanners, useful for hardening tools such as modelscan, Fickling, and…
Medusa🟢⚠️ — AI-first security scanner for AI/ML repos, agents, and MCP surfaces; AGPL-3.0 licensed. (Pantheon Security) ·…
PrivacyRaven🟢🔬 — Privacy-testing library for deep-learning systems, covering model extraction and membership-inference style…
gym-malware🟢🔬 — OpenAI Gym environment for reinforcement-learning agents that mutate PE malware to evade static ML malware…
deep-pwning🟢🔬 — Historical "Metasploit for machine learning" framework for experimenting with adversarial robustness of ML…
open-malicious-code-benchmark🟢🔬 — OMCBench benchmark suite for malicious-code/package detection: labeled Python and JavaScript package archives,…
malicious-software-packages-dataset🟢🔬 — Human-vetted dataset of malicious software packages across npm, PyPI, IDE extensions, and AI Skills, useful for…
GuardDog🟢 — CLI for detecting malicious PyPI, npm, Go, RubyGems, GitHub Actions, and VSCode extension packages using Semgrep…
package-analysis🟢🔬 — Sandboxed static/dynamic analysis pipeline for open-source packages, capturing filesystem, process, and network…
malicious-code-ruleset🟢 — Focused Semgrep ruleset for malicious-code patterns such as dynamic execution and obfuscation, used as an…
pypi_malregistry🔬⚠️ — ASE'23 / USENIX Security'26 malicious-PyPI dataset with more than 10k malicious package versions. — note: no…
Activation-based Model Scanner (AMS)🟢🔬 — PyPI scanner that uses safety-related activation fingerprints to detect degraded or removed safety training and…
PentestGPT🟢🔬 — The original USENIX'24 LLM pentest agent; re-released as an autonomous pipeline with strong benchmark results.…
PentAGI🟢 — Fully autonomous multi-agent pentest framework with Docker sandboxing. (VXControl) · updated 2026-08-06)
CAI – Cybersecurity AI🟢🟠 — Modular, bug-bounty-ready agent framework supporting 300+ LLM models. MIT for research; separate commercial…
Strix🟢 — Autonomous "AI hackers" that dynamically run code and validate vulnerabilities with PoCs (Apache-2.0). · updated…
hackingBuddyGPT🟢🔬 — Minimal (~50 LOC) research framework for LLM-driven Linux priv-esc and web pentesting (FSE'23). · updated…
Nebula🟢🟠 — AI pentesting CLI assistant with local-LLM support (Llama-3.1, Mistral, DeepSeek). · updated 2026-07-26)
HexStrike-AI🟢 — MCP server exposing 150+ security tools (nmap, gobuster, nuclei, …) to AI agents (MIT). · updated 2026-08-03)
Deep Eye🟢 — AI-assisted penetration-testing scanner that orchestrates multiple LLM providers for payload generation, 45+…
Burp Suite MCP Server🟢⚠️ — Official Burp Suite extension exposing Burp to AI clients through MCP. (PortSwigger) — note: GPL-3.0 licensed.…
pentest-ai🟢 — Offensive-security MCP server with 200+ wrapped tools, specialist agents, and OWASP-oriented probes for…
pentest-ai-agents🟢 — Collection of Claude Code offensive-security subagents for authorized penetration-testing research. · updated…
DarkMoon🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and…
T3MP3ST🟢⚠️ — Autonomous offensive-security meta-harness that wraps local or API-backed coding agents into a multi-agent…
Shannon🟢🟠⚠️ — White-box autonomous AI pentester with strong XBOW-benchmark results. Shannon Lite is AGPL-3.0; Shannon Pro…
AIDA🟢⚠️ — Model-agnostic autonomous pentest agent running inside an isolated Docker environment; AGPL-3.0 licensed. ·…
HackSynth🟢🔬⚠️ — Planner/summarizer LLM-agent framework for autonomous penetration testing and benchmark evaluation; AGPL-3.0…
VulnBot🟢🔬 — Multi-agent collaborative penetration-testing framework with RAG support. · updated 2025-04-07)
PentestAgent🟢 — Black-box AI pentest framework with MCP, multi-agent spawning, and persistent sessions. · updated 2026-08-04)
cyber-security-llm-agents🟢⚠️ — AutoGen-based agents for cybersecurity tasks (shown at RSAC 2024). (NVISO) · updated 2024-05-07)
Pentest-Swarm-AI🟢 — Swarm-intelligence multi-agent pentest with stigmergic blackboard coordination (Go). · updated 2026-08-04)
hackGPT🟢⚠️ — LLM offensive-security toolkit. · updated 2026-08-12)
ShiftGrid🟢 — Prompt engine that turns Claude Code into a transparent, human-in-the-loop pentester, structuring engagements…
BugTraceAI🟢⚠️ — Self-hosted autonomous web-application security scanner that combines reconnaissance, specialist exploit…
HunterX🟢 — AI-assisted offensive security engine that orchestrates reconnaissance, security-tool coordination, vulnerability…
MCP Security Hub🟢 — Collection of Dockerized MCP servers that expose offensive-security tools such as Nmap, Nuclei, SQLMap, Ghidra,…
Forefy .context🟢 — MIT-licensed collection of AI-agent Skills, Goals, and Dynamic Workflows for security auditing, authorized…
subwiz🟢 — 🅐 Lightweight nanoGPT model that predicts resolvable subdomains via beam search; model weights are published on…
regulator🟢⚠️ — 🅐 Learns and ranks regex-like naming patterns from known subdomains to generate likely new candidates. — note:…
eyeballer🟢⚠️ — 🅐 Convolutional neural network that classifies pentest/recon screenshots (login pages, webapps, old-looking…
GyoiThon🟢🔬 — 🅐 Machine-learning-assisted web intelligence tool that fingerprints products, versions, CVEs, login pages,…
ffufai🟢⚠️ — 🅑 AI wrapper around the ffuf web fuzzer that suggests file extensions and paths from the target URL and…
PassGPT🔬⚠️ — 🅐 GPT-style password model trained on leaked passwords for research on password generation and strength…
PassGAN🔬 — 🅐 WGAN that learns password distributions from leaks to generate guesses; historical reference implementation of…
neural_network_cracking🔬 — 🅐 RNN password-guessing model from Fast, Lean, and Accurate: Modeling Password Guessability Using Neural…
phishing-url-detection🟢 — 🅐 Packaged URL phishing classifier with ONNX and pickle artifacts. license: MIT · access: open · artifacts:…
Phishing Email Detection DistilBERT v2.4.1🟢 — DistilBERT text-classification model for email and URL phishing detection, trained on a public Hugging Face…
PhishIntention🔬 — 🅐 Deep-vision phishing detector that infers both brand intention and credential-taking intention from webpage…
VisualPhishNet🔬⚠️ — 🅐 Triplet CNN for zero-day phishing detection by visual similarity to trusted websites (ACM CCS 2020). (CISPA)…
SYARA🟢🔬 — 🅐 Semantic YARA-like rule engine for text and multimodal signals, adding embedding similarity,…
AutoYara🟢🔬 — 🅐 Research implementation of automatic YARA rule generation via biclustering over byte n-grams for…
yaraml_rules🟢🔬 — Research code that trains scikit-learn classifiers on malware and benign corpora, then compiles the learned…
RuleLLM🟢🔬 — 🅑 LLM-assisted malware-rule generator that clusters malicious code samples and produces/refines/validates YARA…
DeepSQLi🟢⚠️ — 🅐 Deep-learning SQL-injection detector with dataset, trained models, and a Flask Prediction API for GatewayD…
deepsecrets🟢 — Semantic secrets scanner using lexing/parsing, entropy checks, and hashed-known-secret matching across 500+…
VLAI Vulnerability Severity Classifier🟢🔬 — RoBERTa-based vulnerability-severity classifier trained on CIRCL vulnerability scores to assist triage before…
Cloudflare Security Audit Skill🟢 — Coding-agent skill for a multi-phase source-security audit with reconnaissance, coverage-led hunting, independent…
Mantis🟢🔬 — Security-review skills and an ADK reference harness for vulnerability discovery, triage, reproduction,…
VulnHunter (Capital One)🟢 — Attacker-oriented source-review workflow with forward analysis from exposed entry points, a finding-falsification…
Vulnhuntr🟢 — Zero-shot vulnerability discovery in Python repos via LLM call-chain analysis; credited with a 0-day RCE in…
deepsec🟢 — Agent-powered security harness for scanning large codebases with coding agents, resumable parallel runs, custom…
Codex Security🟠 — CLI and TypeScript SDK that use Codex Security to find, validate, and help fix vulnerabilities in a codebase,…
open·kritt🟢⚠️ — Self-hosted platform that orchestrates Codex or Claude Code across focused vulnerability-research workflows,…
Visa Vulnerability Agentic Harness🟢 — Agentic SAST pipeline for autonomous vulnerability discovery, exploitability verification, SARIF/Markdown…
defending-code-reference-harness🟢 — Reference Claude Code skills and autonomous vulnerability-discovery pipeline for threat modeling, static…
rust-in-peace🟢 — Rust-security fork of Anthropic's defending-code reference harness, adding a Rust profile for agentic review of…
claude-code-security-review🟠 — Official Claude-based semantic SAST GitHub Action that reviews PR diffs. (Anthropic) · updated 2026-02-11)
IRIS🟢🔬 — Neurosymbolic SAST combining LLMs with CodeQL for Java vulnerability detection (MIT). · updated 2026-07-02)
sast-skills🟢 — Agent skills that turn AI coding assistants into a multi-agent SAST scanner. · updated 2026-04-08); Related:…
llm-sast-scanner🟢 — SAST skill for AI coding agents with structured source-to-sink analysis across 34 vulnerability classes. License:…
sast-ai-workflow🟢 — LangGraph workflow for reviewing static-analysis findings, reducing false positives, and producing vulnerability…
llm-security-scanner🟢⚠️ — LLM-powered code scanner that opens GitHub issues for findings. · updated 2025-04-02)
Trail of Bits Skills🟢⚠️ — Claude Code- and Codex-compatible security workflow skills for code review, differential review, false-positive…
OpenHack🟢 — File-based source-guided white-box security-review workspace that orchestrates agents through reconnaissance,…
Buttercup🟢🔬⚠️ — Multi-component cyber reasoning system for finding, validating, and patching software vulnerabilities with…
tachi🟢 — Threat modeling and AI-reasoning vulnerability detection harness for Claude Code that dispatches 14 specialized…
STRIDE GPT🟢 — LLM-powered threat modeling tool that generates STRIDE threat models, attack trees, data flow diagrams, DREAD…
oss-fuzz-gen🟢 — LLM-driven fuzz-harness generation for OSS-Fuzz; reported 26 real vulnerabilities (incl. CVE-2024-9143 in…
PromptFuzz🟢🔬⚠️ — LLM-mutated prompts to generate fuzz drivers for C/C++ libraries (Rust). · updated 2026-05-15)
Fuzz4All🟢🔬 — "Universal" LLM-based fuzzer across compilers/languages (ICSE 2024). · updated 2025-08-11)
ChatAFL🟢🔬 — LLM-guided protocol fuzzing extending AFLNet (NDSS'24). · updated 2025-06-20)
TitanFuzz🟢🔬⚠️ — First LLM-based fuzzer for PyTorch/TensorFlow (ISSTA'23). · updated 2023-09-10)
LLMFuzzer🟢🔬 — First open-source fuzzing framework for LLM API integrations. — note: historical research reference;…
ps-fuzz🟠 — System-prompt hardening fuzzer; 16 attacks × 16 providers. (Prompt Security) · updated 2026-02-16)
FuzzyAI🟠 — Automated LLM fuzzer for jailbreaks/prompt injection. (CyberArk) · updated 2026-02-06)
spikee🟢 — Prompt-injection evaluation and exploitation kit with dataset generation, Burp integration, and pluggable judges.…
promptmap🟢⚠️ — Prompt-injection scanner for custom LLM applications in white-box and black-box modes; GPL-3.0 licensed. ·…
ai-prompt-fuzzer🟢 — Burp Suite extension fuzzing GenAI/LLM prompts. (PortSwigger) · updated 2025-09-04)
trs🟢 — LLM + ChromaDB tool to summarize threat reports and extract MITRE TTPs and IOCs. · updated 2023-11-15)
TI-Mindmap-GPT🟢 — Streamlit app: AI summaries, mindmaps, IOC/TTP extraction, and ATT&CK Navigator layers. · updated 2026-02-16)
aiocrioc🟢 — LLM + OCR IOC extraction (pulls IOCs from images/PDFs). · updated 2024-12-04)
ThreatIngestor🟢 — Extracts/aggregates IOCs from feeds; integrates with MISP/ThreatKB (pairs well with LLM post-processing). ·…
IATelligence🟢 — Explains imported Windows APIs in PE files via GPT and maps to MITRE ATT&CK. · updated 2022-12-09); Related:…
MCP_Security🟢⚠️ — MCP server (ORKL) for querying the ORKL threat-intel API. · updated 2025-01-22); Related: IATelligence
threat-intelligence-cti-analysis🟢 — NLP/LLM pipeline for IOC extraction, MITRE ATT&CK mapping, and knowledge-graph generation from unstructured CTI.…
CTINexus🟢🔬 — LLM-assisted framework for data-efficient extraction of cyber-threat intelligence and construction of…
CTIBench🔬⚠️ — NeurIPS 2024 Spotlight benchmark with 4,610 examples across CTI knowledge, CWE root-cause mapping, CVSS…
CTI-BERT🟢🔬 — BERT model pretrained from scratch on a large cybersecurity text corpus for downstream CTI extraction,…
AI-SOC-Agent🟢 — Black Hat 2025 MCP server exposing security-investigation tools (ELK, IRIS). · updated 2025-12-28)
soctalk🟢 — LangGraph SOC automation agent with MCP integrations for Wazuh, Cortex, TheHive, and MISP plus mock-agent test…
Vigil SOC🟢 — Open-source AI SOC with readable Python agents, Markdown playbooks, and MCP integrations for triage,…
agentic-soc-platform🟢 — Agentic SOC platform (LangGraph/Dify) with local-LLM support. · updated 2026-08-05)
SigmAIQ🟢⚠️ — pySigma wrapper and LangChain toolkit for automatic Sigma rule creation and translation; LGPL-2.1 licensed.…
RulePilot🟢🔬 — LLM-powered security-rule generation agent for Splunk, Microsoft Sentinel, and Elastic, with field detection…
SOCGPT🟢 — LLM log summarization, severity triage, MITRE mapping, and Q&A. · updated 2025-06-11)
AttackGen🟢 — LLM-driven incident-response scenario generator using MITRE ATT&CK + ATLAS. · updated 2026-08-13)
Google Security Operations and Threat Intelligence MCP Server🟢 — MCP servers and packages that let MCP clients access Google Security Operations, SOAR, Google Threat…
ExCyTIn-Bench (SecRL)🟢🔬 — ICML 2026 benchmark for evaluating LLM agents on cyber-threat investigation and threat hunting through security…
DeepZero🟢🔬 — Resumable Windows driver research framework combining Ghidra decompilation, static analysis, and optional LLM…
Gepetto🟢 — IDA Pro plugin: GPT adds comments and meaningful variable names. · updated 2026-08-15)
ida-pro-mcp🟢 — MCP bridge for IDA Pro exposing decompile, disassemble, xref, rename, and debugging workflows to LLM clients. ·…
GhidraMCP🟢 — MCP server exposing Ghidra reverse-engineering ops to any MCP-capable LLM. · updated 2025-06-23); Related:…
ReVa🟢 — Ghidra-focused reverse-engineering assistant with MCP support, Claude Skills integration, and long-form analysis…
GhidrAssistMCP🟢 — Native Ghidra MCP extension with broad tool coverage, headless support, and security-sensitive tool gating. ·…
ghidra-mcp🟢 — Ghidra MCP server with large tool coverage, GUI plugin, headless server, and lazy tool loading. · updated…
GhidrOllama🟢⚠️ — Ghidra script using the Ollama API for function analysis/renaming. · updated 2024-11-29); Related: OGhidra ·…
GhidraGPT🟢 — Ghidra plugin that integrates LLMs for automated code refactoring and analysis. · updated 2026-07-22); Related:…
LLM4Decompile🟢🔬⚠️ — Research project for binary-to-C decompilation with LLMs; code is MIT, but model weights use a more…
x64dbg_mcp🟢 — MCP server exposing x64dbg debugging and reverse-engineering operations to AI clients. · updated 2026-06-08)
binaryninja-mcp🟢 — MCP server for Binary Ninja-assisted reverse engineering. · updated 2025-05-13)
OGhidra🟢 — Natural-language Ghidra analysis via Ollama. (Lawrence Livermore National Lab) · updated 2026-08-14); Related:…
ghidra_tools (G-3PO)🟢 — Ghidra plugin for AI-assisted decompiled-code analysis. (Tenable) · updated 2023-05-10)
gpt-wpre🔬 — Whole-program reverse engineering with GPT-3. · updated 2022-12-31)
burpgpt🟢 — Burp Suite extension integrating GPT for passive scanning. · updated 2024-06-09); Related: Burp-extension-for-GPT
Burp-extension-for-GPT🟢 — Burp extension to analyze HTTP traffic with GPT. (Tenable) · updated 2023-05-01); Related: burpgpt
REA🟢 — Local CLI and MCP toolkit for agent-assisted reverse engineering of native binaries, managed PE/CLI files,…
Open-ReverseLab🟢⚠️ — Agent-native reverse-engineering workspace and MCP server combining Ghidra headless analysis with Frida,…
RAMPART🟢 — Pytest-native framework for repeatable adversarial and benign safety regression tests against AI agents, with…
Agent OPFOR🟢 — Adversary-emulation toolkit for AI agents, LLM applications, and MCP servers with multi-turn attack templates,…
NuGuard🟢 — Generates an AI-SBOM, statically analyzes agentic applications, red-teams live targets for prompt injection/tool…
garak🟢 — The LLM vulnerability scanner — probes for prompt injection, jailbreaks, data leakage, and more. (NVIDIA) ·…
PyRIT🟢 — Python Risk Identification Tool; battle-tested across 100+ GenAI red-team operations. (Microsoft) · updated…
promptfoo🟢 — LLM eval + red-teaming/pentesting CLI with 50+ attack plugins (MIT). Note: OpenAI announced an acquisition…
Augustus🟢 — Single-binary LLM security testing framework for prompt injection, jailbreaks, and adversarial attacks across…
agentic_security🟢 — Agentic LLM vulnerability scanner and AI red-team kit for jailbreaks, prompt injection, fuzzing, and API stress…
HackAgent🟢 — Python SDK and CLI for red-teaming AI agents with research-backed attacks such as AdvPrefix, AutoDAN-Turbo, PAIR,…
wallbreaker🟢🔬⚠️ — Claude-Code-style terminal and red-team harness for authorized LLM safety testing, with HarmBench, PAIR/TAP,…
HiveTrace Red🟢 — Early-stage LLM red-teaming framework with 80+ attack templates, async evaluation pipelines, WildGuard…
DeepTeam🟢 — Open-source framework for red-teaming LLMs and LLM systems across jailbreaks, prompt injection, data leakage, and…
Moonshot🟢 — Modular tool for benchmarking, red-teaming, and evaluating LLM applications with custom connectors and recipes.…
Guardrails AI🟢 — Python framework for adding input/output guards, validators, structured-output controls, and Guardrails Hub…
Giskard🟢 — Open-source evaluation, testing, and red-teaming framework for LLM agents, including agent vulnerability scanning…
LangKit🟢 — LLM monitoring toolkit extracting safety/security signals such as jailbreak similarity, prompt-injection…
LLM Guard🟢 — Suite of input/output scanners (PII, prompt injection, etc.). (Protect AI) — note: archived by the maintainer;…
Rebuff🟢 — Archived prompt-injection detector (heuristics + LLM + vector DB + canary tokens). (Protect AI) — note: archived…
NeMo Guardrails🟢 — Programmable guardrails (input/output/dialog/retrieval rails) for LLM apps. (NVIDIA) · updated 2026-08-17)
PurpleLlama🟢 — Llama Guard classifiers, CodeShield, and CyberSecEval. (Meta) · updated 2026-08-14)
LLAMATOR🟢⚠️ — Red-teaming framework for chatbots and GenAI systems; CC BY-NC-SA 4.0 licensed. · updated 2026-01-15)
Vigil🟢🔬 — Library/REST API to scan prompts and responses for prompt injection. · updated 2024-01-31)
Counterfit🟢 — ML/AI penetration-testing automation tool. (Microsoft) · updated 2025-07-18)
AI-Red-Teaming-Playground-Labs🟢 — CTFd-based AI red-team training challenges. (Microsoft) · updated 2025-10-07)
EasyJailbreak🟢🔬 — Framework for building and testing adversarial jailbreak prompts. · updated 2026-03-30)
TextAttack🟢🔬 — Python framework for adversarial attacks, data augmentation, and training for NLP models; useful for robustness…
GPTFuzz🟢🔬 — Research framework for red-teaming LLMs with auto-generated jailbreak prompts. · updated 2026-02-27)
HarmBench🟢🔬 — ICML 2024 standardized evaluation framework for automated red-teaming and robust-refusal benchmarking. (Center…
llm-attacks (GCG)🟢🔬 — Canonical Greedy Coordinate Gradient adversarial-suffix attack implementation for transferable attacks on…
nanoGCG🟢 — Fast, lightweight PyTorch implementation of the GCG adversarial-suffix algorithm. · updated 2025-05-13); Related:…
JailbreakBench🟢🔬 — NeurIPS 2024 open robustness benchmark and leaderboard for generating and defending against LLM jailbreaks. ·…
Open-Prompt-Injection🟢🔬 — Open-source toolkit and benchmark for implementing and evaluating prompt-injection attacks, defenses, and…
PINT Benchmark🟢🔬 — Prompt-injection test benchmark for evaluating detectors and guardrails across multilingual prompt injection,…
PIArena🟢🔬 — ACL 2026 toolbox and benchmark for prompt-injection attacks and defenses, with ready-to-use attacks/defenses,…
Whistleblower🟢⚠️ — Offensive testing tool for inferring system prompts and discovering capabilities of LLM applications exposed…
LLMmap🟢🔬 — Minimal-query fingerprinting tool for identifying LLMs from behavioral traces, with a pretrained open-set…
llm-security🔬 — Original PoC for indirect prompt-injection attacks. · updated 2025-07-17)
JailbreakLLMs🔬⚠️ — Research dataset of 6,387 ChatGPT prompts, including in-the-wild jailbreak prompts from Reddit, Discord,…
Do-Not-Answer🟢🔬 — Dataset for evaluating LLM safeguards on unsafe or policy-sensitive prompts. · updated 2024-06-07)
prompt-injection-defenses🟢⚠️ — Curated catalog of practical defenses against prompt injection. · updated 2025-02-22)
little-canary🟢🔬 — Prompt-injection preflight sensor that probes untrusted input with a powerless canary model and returns PASS,…
Kiji Privacy Proxy🟢 — Local privacy proxy for OpenAI-compatible AI API traffic that detects and masks 26 PII types with an ONNX model…
Anamorpher🟢🔬 — Research tool with a frontend and Python API for crafting and visualizing image-scaling attacks that reveal…
Prompt SIREN🟢🔬 — Research workbench for developing and evaluating prompt-injection attacks and defenses with state-machine agent…
Argus🟢🔬 — Black-box red-team framework for LLM applications and agents with target adapters, attack probes, deterministic…
Cryptex OSS🟢🟠 — Browser-based and self-hostable adversarial prompt workbench with transformation pipelines, campaign workflows,…
API Relay Audit🟢⚠️ — Local audit CLI for third-party LLM relays and proxies, testing prompt injection, model substitution, tool-call…
AIDR Bastion🟢🟠⚠️ — Runtime input-protection service combining detection rules, similarity search, classifiers, optional LLM…
CaMeL🟢🔬 — Research implementation of the capability-based CaMeL interpreter architecture for separating trusted control…
Meta SecAlign🔬⚠️ — Research code, training recipe, and evaluation harness for prompt-injection-resistant Meta SecAlign models…
Wolf Defender Prompt Injection🟢 — Hugging Face text-classification model for prompt-injection detection in agents, chatbots, and CI workflows.…
DeBERTa v3 Prompt Injection v2🟢 — Apache-licensed prompt-injection classifier usable via Transformers pipelines and ONNX. (Protect AI) license:…
PromptGuard🟢⚠️ — ModernBERT-based prompt-injection and jailbreak classifier. (CodeIntegrity AI) license: Apache-2.0 · access:…
Prompt Guard 86M🟠⚠️ — Meta prompt-injection and jailbreak classifier from the Llama Guard family. (Meta) license: Llama 3.1 · access:…
prompt-injection-sentinel🔬⚠️ — ModernBERT-large classifier for prompt-injection and jailbreak detection. (Qualifire) license: other · access:…
SecGPT🟢 — Open cybersecurity-tuned LLM family for vulnerability analysis, log/traffic investigation, anomaly detection,…
Antares-1B🟢⚠️ — Open-weight security SLM specialized for agentic vulnerability localization: it explores repository snapshots…
Trendyol Cybersecurity LLM v2 70B🟢 — Defense-focused cybersecurity LLM based on Llama-3.3-70B, trained on an alignment-safe security instruction…
WhiteRabbitNeo 2.5 Qwen Coder 7B🟢⚠️ — Cybersecurity-oriented Qwen2.5-Coder fine-tune positioned for offensive and defensive security assistance.…
Lily-Cybersecurity-7B-v0.2🟢 — Mistral-7B-Instruct fine-tune for cybersecurity assistance, trained on hand-crafted security and hacking-related…
RavenX CyberAgent 35B Q4_K_M🟢⚠️ — GGUF security-specialized text-generation model positioned for pentest, bug-bounty, tool-calling, MCP,…
Beelzebub🟢⚠️ — Low-code honeypot using LLMs to simulate SSH/HTTP/MCP services (Go). — note: GPL-3.0 licensed. · updated…
DECEIVE🟢🔬 — Proof-of-concept LLM-powered SSH honeypot that evaluates sessions as benign, suspicious, or malicious. (Splunk)…
TRAP🟢🔬 — Research code for Targeted Random Adversarial Prompt honeypots that identify black-box LLM usage through…
shelLM🟢🔬 — LLM-powered SSH honeypot (paper "LLM in the Shell"). · updated 2026-06-25); Related: VelLMes
VelLMes🟢🔬 — Multi-protocol LLM honeypot framework (successor to shelLM). · updated 2025-02-18); Related: shelLM
llm-honeypot🔬⚠️ — Cowrie SSH honeypot extended with prompt-injection traps to detect LLM hacker agents. (Palisade Research) ·…
Inspect Cyber🟢🔬 — Installable Inspect extension for defining and running agentic cyber evaluations with standardized YAML…
GenAI Red Team Lab🟢🔬 — Collection of intentionally vulnerable GenAI sandboxes, exploitation examples, and tutorials for prompt…
SWE-agent (EnIGMA)🟢🔬 — EnIGMA offensive-CTF mode; SOTA on NYU CTF, InterCode-CTF, and Cybench (v0.7 branch). · updated 2026-07-16);…
Cybench🔬 — 40 professional CTF tasks across 4 competitions; widely used by AI safety institutes. · updated 2026-07-09)
NYU CTF Bench🔬 — Dockerized CSAW CTF challenges for LLM-agent evaluation. · updated 2025-09-22)
CTFTiny🔬⚠️ — Lightweight CTF benchmark from the NYU LLM CTF group; GPL-2.0 licensed. · updated 2026-03-10); Related: NYU CTF…
InterCode🔬 — Interactive-coding benchmark incl. InterCode-CTF. · updated 2024-05-05)
inspect_evals🟢🔬 — Maintained Inspect AI evaluation suite containing multiple cyber benchmarks and tasks. (UK AI Security…
BountyBench🔬 — 25 real systems / 40 bug bounties for Detect-Exploit-Patch evaluation. · updated 2025-06-22)
Cyber-Zero🔬 — Trains cybersecurity agents without runtime; ships an EnIGMA+ scaffold. (Amazon Science) — note: archived…
ExploitBench🔬 — Measures AI-agent progress on V8/Chromium exploit ladders. · updated 2026-07-04)
AI Goat🟢🔬⚠️ — Vulnerable-by-design local LLM CTF for learning prompt injection, insecure output handling, data leakage,…
AIGoat🟢🔬⚠️ — Local-first vulnerable LLM security playground with guided OWASP LLM Top 10 attack labs, CTF challenges,…
LLMVault🟢🔬 — Intentionally vulnerable LLM security-training platform with OWASP LLM Top 10 labs, CTF-style challenges,…
Damn Vulnerable LLM Agent🟢🔬 — Deliberately vulnerable LangChain ReAct agent for practicing prompt-injection and Thought/Action/Observation…
claude-bug-bounty🟢 — Claude Code plugin orchestrating recon → vuln classes → reporting. · updated 2026-08-10)
Bug-Bounty-Agents🟢 — 43 AI agent personas for Claude Code / Copilot / Cursor across the bug-bounty lifecycle. · updated 2026-04-30)
ai-exploits🟢 — Real-world AI/ML exploits (Metasploit modules + Nuclei templates) for MLflow, Ray, H2O. (Protect AI) · updated…
CyberGym🟢🔬 — Large-scale evaluation framework for AI-agent vulnerability analysis on real-world tasks, with locally deployed…
CVE-Bench🟢🔬 — ICML 2025 benchmark that evaluates AI agents against reproducible Docker environments for real…
SCAM🟢🔬 — Benchmark for measuring whether tool-using agents recognize and resist realistic scams, social engineering,…
AIRTBench-Code🟢🔬 — Research harness and dataset for evaluating autonomous AI red-team agents on AI/ML security CTF challenges,…
AI-Goat (Orca Security)🟢🔬 — Deliberately vulnerable AWS and Terraform lab for learning AI/ML infrastructure risks such as model…
LivePI🔬⚠️ — Reproducibility artifact for a production-like indirect prompt-injection benchmark spanning live but…
EscalateGPT🟢 — GPT-based discovery of privilege-escalation paths in AWS IAM policies. (Tenable) · updated 2024-01-17)
Cynative🟢 — Local AI security research agent for cloud, code, and runtime environments across GitHub, GitLab, AWS, GCP,…
Julius🟢 — Local Go tool that fingerprints LLM service infrastructure on authorized endpoints, identifies 60+ serving,…
MemoryInvestigator🔬 — Volatility 3 + LLM + RAG for memory-forensic triage. · updated 2025-09-16); Related: Volatility-MCP-Server
Volatility-MCP-Server🟢 — MCP exposing Volatility 3 plugins for natural-language memory forensics. · updated 2025-07-07); Related:…
llm_osint🟢🔬 — Proof-of-concept LLM OSINT framework using knowledge and web agents for internet research workflows. · updated…
ai_osint🟢 — Curated AI-OSINT dorks, queries, and techniques for discovering exposed LLM and AI infrastructure. · updated…
PhishLLM🔬⚠️ — Reference-less phishing detection via LLM brand recognition (USENIX'24). · updated 2026-06-04); Related: PhishVLM
mcp-dnstwist🟢 — MCP server for dnstwist DNS fuzzing to support typosquatting, phishing, and lookalike-domain analysis. · updated…
osintgpt🟢⚠️ — OpenAI embeddings + Qdrant over OSINT corpora. · updated 2023-12-11)