GitHub repo leaderboard by stars, growth rate and activity.
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go, Claude API, and 7+ native security tools.
Automatic SSTI detection tool with interactive interface
LuaN1aoAgent is a fully autonomous AI-driven penetration testing agent powered by graph-based cognitive reasoning.
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
Statically-linked ssh server with reverse shell functionality for CTFs and such
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | Fully autonomous AI Agents system capable of performing complex penetration testing tasks | Go | 22,779 | last pushed 23 hours ago | |
| 2 | Next generation web scanner | Ruby | 6,830 | last pushed 5 months ago | |
| 3 | Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines). | Python | 4,450 | last pushed 1 year ago | |
| 4 | 基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。 | Python | 3,302 | last pushed 6 days ago | |
| 5 | Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go, Claude API, and 7+ native security tools. | Go | 2,488 | last pushed 3 days ago | |
| 6 | Automatic SSTI detection tool with interactive interface | Python | 1,638 | last pushed 2 weeks ago | |
| 7 | SSH based reverse shell | Go | 1,458 | last pushed 3 days ago | |
| 8 | LuaN1aoAgent is a fully autonomous AI-driven penetration testing agent powered by graph-based cognitive reasoning. | TypeScript | 1,304 | last pushed 3 weeks ago | |
| 9 | Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/). | Go | 1,206 | last pushed 8 months ago | |
| 10 | Statically-linked ssh server with reverse shell functionality for CTFs and such | Go | 1,056 | last pushed 2 months ago |
All · 11,658