Security testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties
Security testing that runs inside the coding agent you already use. Source-available, not open source.
A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com
Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks

MCPify is an AI enablement compiler that transforms existing applications into AI-native, agent-operable systems.
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.
Composable agent runtime with enforced isolation boundaries
Containment for AI agents - user isolation, sandboxed execution, network controls, backup/rollback. TLA+ verified.
MCP server that enables AI agents to perform comprehensive web audits using Google Lighthouse with 13+ tools for performance, accessibility, SEO, and security analysis.
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Multi-language agent runtime and library for execution scope management, lifecycle events, and middleware on tool and LLM calls.
OpenGhost is an Agent Skill for authorized web app penetration testing: Enter lab url paste credential your agent and wait everything does with help of openghost
Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
Open-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.
Observability and enforcement for AI agent harnesses. Capture every run and runtime reliability with policy enforcement. 40 built-in policies, a local dashboard, no account required with a generous free cloud plan
Agent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, in the browser, or in the cloud.
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0