GitHub repo leaderboard by stars, growth rate and activity.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Find, verify, and analyze leaked credentials
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Database governance built for humans and agents — controlling changes and access across every major database.
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production. | TypeScript | 47,904 | last pushed 2 days ago | |
| 2 | Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more | Go | 37,861 | last pushed 13 hours ago | |
| 3 | 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0 | Python | 32,587 | last pushed 2 weeks ago | |
| 4 | Find secrets with Gitleaks 🔑 | Go | 29,223 | last pushed 2 days ago | |
| 5 | Find, verify, and analyze leaked credentials | Go | 27,769 | last pushed 9 hours ago | |
| 6 | Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. | JavaScript | 21,745 | last pushed 2 days ago | |
| 7 | Database governance built for humans and agents — controlling changes and access across every major database. | Go | 14,476 | last pushed 1 hour ago | |
| 8 | Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks. | Go | 11,779 | last pushed 19 hours ago | |
| 9 | 🛡️ Open-source and cloud-native Web Application Firewall (WAF) | Python | 10,932 | last pushed 2 hours ago | |
| 10 | OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security | TypeScript | 10,638 | last pushed 2 hours ago |
All · 11,658