GitHub repo leaderboard by stars, growth rate and activity.
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
AI-powered bug bounty hunting toolkit that works with or without subscription.
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.
Learn to code securely while having fun through our popular open source in-editor experience, designed for developers, students, and anyone curious about security. Get started for free in under 2 minutes, playing right from your browser.
Open-source AI-powered offensive security harness for automated penetration testing.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | Open-source AI penetration testing tool to find and fix your app’s vulnerabilities. | Python | 61,565 | last pushed Yesterday | |
| 2 | Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production. | TypeScript | 47,886 | last pushed 2 days ago | |
| 3 | This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org | Jupyter Notebook | 29,348 | last pushed 4 days ago | |
| 4 | Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them. | Python | 16,801 | last pushed Yesterday | |
| 5 | OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security | TypeScript | 10,611 | last pushed 22 hours ago | |
| 6 | A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation. | Python | 6,215 | — | last pushed 22 hours ago |
| 7 | AI-powered bug bounty hunting toolkit that works with or without subscription. | Python | 4,734 | last pushed 6 days ago | |
| 8 | secure multiplexed execution paths for agents - zero trust, zero setup, zero latency. | Rust | 4,026 | last pushed Yesterday | |
| 9 | Learn to code securely while having fun through our popular open source in-editor experience, designed for developers, students, and anyone curious about security. Get started for free in under 2 minutes, playing right from your browser. | JavaScript | 2,823 | last pushed 23 hours ago | |
| 10 | Open-source AI-powered offensive security harness for automated penetration testing. | TypeScript | 2,663 | last pushed Yesterday |
All · 11,474