Security testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties
Security testing that runs inside the coding agent you already use. Source-available, not open source.
Tool-agnostic 13-phase AI development pipeline — turns a task description into reviewed, committed code through automated design, adversarial review, security, test, and code-review gates. One bash engine, balanced Opus/Sonnet routing, self-healing commit review.
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
A local MCP runtime that attacks what you own and only reports what it proved. 17 CVEs across 9 projects came out of this repo. Install: npx -y hacker-bob@latest install /path/to/project, then run /bob-evaluate target.com
Master Claude Code Hooks
Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks

MCPify is an AI enablement compiler that transforms existing applications into AI-native, agent-operable systems.
A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.
Composable agent runtime with enforced isolation boundaries
Containment for AI agents - user isolation, sandboxed execution, network controls, backup/rollback. TLA+ verified.
MCP server that enables AI agents to perform comprehensive web audits using Google Lighthouse with 13+ tools for performance, accessibility, SEO, and security analysis.
ADR secures enterprise AI agents through observability, security benchmarking, and threat detection. Deployed at Uber.
All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, and submission-ready reports for HackerOne, Bugcrowd, Intigriti & Immunefi.
AI-powered bug bounty hunting toolkit that works with or without subscription.
Multi-language agent runtime and library for execution scope management, lifecycle events, and middleware on tool and LLM calls.
OpenGhost is an Agent Skill for authorized web app penetration testing: Enter lab url paste credential your agent and wait everything does with help of openghost
Tamper-evident integrity monitor for the MCP config & server files your local AI agents load.
A plugin-based gateway that orchestrates other MCPs and allows developers to build upon it enterprise-grade agents.
Blackhat 2025 presentation and codebase: AI SOC agent & MCP server for automated security investigation, alert triage, and incident response. Integrates with ELK, IRIS, and other platforms.
Local-first MCP security scanner for AI-generated apps. Scan → fix → rescan from Claude Code, Cursor, Codex, and other agents.
Verifiable and free cloud compute for AI agents. webMCP + MCP native. Check out our sandboxed Beta + research in the README
Open-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.
Observability and enforcement for AI agent harnesses. Capture every run and runtime reliability with policy enforcement. 40 built-in policies, a local dashboard, no account required with a generous free cloud plan