PyPI96Exceptionalhealth index
Python★ 10.3K↓ 34.4K/moAug 11, 2026
npm96Exceptionalhealth index

promptfoo/promptfooTest your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
TypeScript★ 23.9K↓ 2.1M/moAug 5, 2026
—94Exceptionalhealth index
OWASP/mastgThe OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
Python★ 13.1KAug 3, 2026
PyPI · Go · npm94Exceptionalhealth index
Python · Cypher★ 5,348↓ 7,794/moAug 28, 2026
npm · RubyGems90Excellenthealth index

dradis/dradis-ceDradis Framework: Collaboration and reporting for IT Security teams
Ruby · HTML★ 841Sep 5, 2026
owasp-noir/noirHunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
Crystal★ 1,363Aug 4, 2026
Go89Excellenthealth index
praetorian-inc/nervaFast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian
Go★ 316Jul 17, 2026
PyPI89Excellenthealth index

soxoj/maigret🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Python · HTML★ 36.1K↓ 99.4K/moAug 5, 2026
PyPI88Excellenthealth index
Python★ 88.2K↓ 111.4K/moAug 4, 2026
npm87Excellenthealth index

pensarai/apexAI-powered offensive security testing using autonomous agents, directly in your terminal.
TypeScript★ 307↓ 7,921/moSep 6, 2026
npm84Excellenthealth index

KeygraphHQ/shannonShannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/moAug 5, 2026
Go · PyPI84Excellenthealth index

adithyan-ak/AgentHoundOffensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.
Go · TypeScript★ 270Aug 22, 2026
PyPI83Excellenthealth index
Python★ 6,698↓ 917/moAug 29, 2026
Go81Excellenthealth index
Go★ 16.5KAug 5, 2026
PyPI80Excellenthealth index
Python★ 6,190↓ 2.1M/moAug 12, 2026
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026
PyPI · crates.io78Goodhealth index
Python★ 14.6K↓ 32.4K/moAug 19, 2026
Go★ 1,045Jul 30, 2026
Python · JavaScript★ 1,093↓ 188/moJul 17, 2026
RAJANAGORI/NightingaleNightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes preconfigured with all essential tools and utilities required for efficient Vulnerability Assessment and Penetration Testing (VAPT), streamlining the setup process for security professionals.
Dockerfile · Shell · Python★ 313Aug 4, 2026
Go★ 3Sep 5, 2026
go-appsec/toolboxCollaborative application security testing between humans and agents via CLI and MCP
Go★ 37Jul 17, 2026
ASCIT31/Dark-MoonAutonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
Python · TypeScript · Shell★ 802Aug 4, 2026
TypeScript★ 9↓ 15K/moSep 5, 2026
chainreactors/aiscanAI-driven pi-like agent for cyber security — single binary for pentest, red team, bug bounty
Go · TypeScript★ 218Jul 28, 2026
Go★ 3Jul 17, 2026
Python★ 23↓ 752/moJul 26, 2026
raccioly/websec-validatorLocal-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 2Jul 31, 2026
ddddddO/packemonPacket monster (っ‘-’)╮=͟͟͞͞◒ ヽ( '-'ヽ) TUI tool for sending packets of arbitrary input and monitoring packets on any network interfaces (default: eth0). Windows/macOS/Linux
Go★ 305Jul 20, 2026

hahwul/goriA fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.
Crystal★ 63Aug 11, 2026