security-tools

31 servers · 1,950★ total

一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。

🚀 自动化资产侦察与漏洞监控平台 (ARL-Next)。重构自经典 ARL,全面升级 Puppeteer + Nuclei 引擎,打通「天眼查/ICP ➔ 资产发现 ➔ 漏洞扫描 ➔ 威胁情报追踪」安全闭环。支持 Docker 极简部署,AI 二开友好。

Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.

AI-powered MCP server for Burp Suite Professional — 149 tools across proxy, scanner, inline fuzzer, race conditions, guided injection, JWT/IDOR attacks, recon & OOB, with a real-time dashboard and hardened localhost security. Drive Burp from Claude Code or any MCP client.

Reticle intercepts, visualizes, and profiles JSON-RPC traffic between your LLM and MCP servers in real-time, with zero latency overhead. Stop debugging blind. Start seeing everything.

AI-Powered Offensive Security Research Engine - desktop-native security testing platform with native MCP integration. 90 tools, MITM proxy, stealth browser, autonomous AI agent. Built on Tauri + Rust + React.

Collaborative application security testing between humans and agents via CLI and MCP

One command installs 670+ security tools on Linux & Termux. Its authorization-gated MCP server works with Claude Code, OpenCode, Codex, Gemini CLI, Ollama-backed agents and other MCP clients. Includes 870+ agent skills for CTF, pentesting, bug bounty, DFIR and red/blue teams—companion by default, autonomous when asked.

RamiBot v3.8.0 is a local-first AI security operations platform integrating multi-LLM support, a dynamic red/blue team skill pipeline, MCP tool orchestration, Docker terminal access, Tor proxy management, and an auto-integrated Kali-based tool server (rami-kali) for controlled, extensible offensive and defensive workflows

MCP server for authorized pentest workflows: Nmap/Gobuster orchestration, context aggregation, AI-assisted triage, and reporting.

Detonate files & URLs in cloud malware sandboxes (Hybrid Analysis, tria.ge, ANY.RUN) and enrich IOCs across MalwareBazaar, ThreatFox, URLhaus, Feodo, URLScan & VirusTotal — straight from Claude. BYOK, async, MITRE ATT&CK.

Open-source AI security platform providing perimeter defense for LLMs and AI agents through swarm analysis, policy enforcement, adversarial testing, and real-time threat detection.

Headless CLI reflection debugger for .NET assemblies with MCP server support

[CyberChef-MCP] Model Context Protocol Server for CyberChef ... exposing GCHQ's "Cyber Swiss Army Knife" as 463+ executable AI agent tools spanning encryption, encoding, compression, and forensic data analysis

Local credential control for AI coding agents.

MCP server bridging Kali and FlareVM for automated Windows malware analysis. 48 tools, 5 prompts, 5 resources, composite playbooks (triage, behavioral, unpack, persistence audit).

Burp MCP Security Analysis Toolkit

Agentic-DART — autonomous detection & response agent. Architecture-first, not prompt-first. Starts as agentic DFIR; designed to expand toward agentic SOC and beyond.

AI-driven pentest orchestration that hands Claude the full PTES methodology over real MCP tool calls. 80+ tools, 33 verification probes, scope guard on every request. Python orchestrator + React/Ink TUI.

Discover and audit MCP servers for security vulnerabilities across Claude Code, Cursor, VS Code, and more

Offensive security framework for AI agents and MCP servers.

Runtime policy enforcement and audit control plane for MCP tool execution. Deterministic, non-AI policy engine that intercepts MCP tools/call requests before execution.

Local-first permission gateway for AI agents: connector-based SSH, Postgres, and Redis access with scoped tokens, human approval, audit logs, and encrypted local credentials.

Universal cyber assistant: ~80 audited Kali tools + an expert skills library, driven by any model over MCP or direct run

Agentic MCP for Roblox. Run tests and find exploits in your game from Claude Code, Codex, or Gemini.

Given an MCP server, shows the declared ToolAnnotations for security assessments

Security vulnerability scanner for VS Code. Scans dependencies for CVEs from NVD/OSV databases. Integrates with GitHub Copilot via Model Context Protocol. Supports npm, pip, Maven, Go, Rust, and more.

CLI-first, deterministic architecture intelligence. Builds an offline model of your repo to answer impact, cycles, dead code, duplication and security, and enforces your architecture as a contract in CI. No LLM in the loop; usable by coding agents over MCP or directly via CLI.

Description: Local-first pre-commit policy guard for AI-agent repositories. Website: https://pypi.org/project/aigenguard/

Security linter for environment variables, Docker, CI, Kubernetes, and runtime configuration.

Local-first MCP server that gives sandboxed Codex a narrow, auditable Git workflow surface.