AI Security Matrix

A curated list of AI-enabled security testing tools.

Last updated Category ToolScope Stars Flags
today agent Armur-Ai/Pentest-Swarm-AI new
Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go and 7+ native security tools.
webappnetworkrecon 2.5k rootinstalls
today scanner promptfoo/promptfoo new
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
llmagentic 25k rootcredentialsinstallscalls outopaque
today scanner snyk/agent-scan new
Security scanner for AI agents, MCP servers and agent skills.
agentic 3.0k rootcredentialsinstalls
today scanner Tencent/AI-Infra-Guard new
A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
llmagentic 6.4k rootcredentialsinstallscalls out
today scanner Lab700xOrg/aisbom new
Static security scanner for ML model files — detects pickle bombs, Keras Lambda RCE and GGUF template injection, and generates CycloneDX / SPDX AI-BOMs (AIBOM) as EU AI Act, CRA and FDA §524B evidence.
modfile 77 none
today scanner promptfoo/modelaudit new
Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment
modfile 70 rootcredentialscalls out
1d agent samugit83/redamon new
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
redteamadnetworkrecon 2.4k rootcredentialsinstallscalls outopaque
1d scanner microsoft/PyRIT new
The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to proactively identify risks in generative AI systems.
llm 4.5k rootinstallscalls outopaque
1d skill trailofbits/skills new
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
agenticbinarycodewebapp 7.1k rootcredentialsinstalls
1d agent AIPentest/CyberStrikeAI new
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
networkwebapp 6.7k rootcredentialsinstallsopaque
1d scanner cisco-ai-defense/mcp-scanner new
Scan MCP servers for potential threats & security findings.
agentic 1.1k rootcredentials
2d agent usestrix/strix new
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
webappapicode 63k rootcredentialsinstallscalls out
2d agent ipa-lab/hackingBuddyGPT new
Helping Ethical Hackers use LLMs in 50 Lines of Code or less..
network 1.2k root
2d agent berylliumsec/nebula new
AI-powered penetration testing assistant for automating recon, note-taking, and vulnerability analysis.
networkrecon 1.1k rootcalls out
2d agent dreadnode/ares new
Ares is an autonomous security operations platform where LLM-driven red and blue team agents operate against each other on live infrastructure, enabling realistic evaluation of attack and defense.
adnetworkredteam 73 rootcredentialsinstallsopaque
2d agent 0xSteph/pentest-ai new
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
webappnetwork 1.7k rootinstalls
2d agent xalgorix/xalgorix new
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
reconwebappnetwork 1.1k rootcredentialsinstallscalls out
3d scanner adithyan-ak/AgentHound new
Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.
agentic 434 rootcredentialsinstalls
4d scanner msoedov/agentic_security new
Agentic LLM Vulnerability Scanner / AI red teaming kit 🧪
llmagentic 2.0k calls out
4d skill Security-Phoenix-demo/security-skills-claude-code new
This repository is a curated collection of skills, plugins, and automation pipelines designed for Claude Code — Anthropic's CLI for AI-assisted software engineering. It was built by the engineering and security engineering teams at Phoenix Security and released as open source so that security professionals, DevSecOps engineers, AppSec teams
code 73 root
5d agent vxcontrol/pentagi new
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
webappnetworkrecon 24k binariesrootcredentialsinstalls
5d scanner trailofbits/fickling new
A Python pickling decompiler and static analyzer
modfile 668 credentialsinstallsopaque
6d scanner NVIDIA/garak new
the LLM vulnerability scanner
llm 9.2k root
8d agent GH05TCREW/pentestagent new
PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.
webappapi 3.1k root
8d skill Masriyan/Claude-Code-CyberSecurity-Skill new
22 production-quality Claude Code Skills for cybersecurity professionals — covering offensive security, defensive operations, reverse engineering, threat hunting, threat intelligence, purple team / adversary emulation, CSOC automation, AI/LLM security, mobile, OT/ICS, GRC, software supply chain security, and more.
redteambinaryllm 419 rootinstalls
9d mcp mpgn/NetExec-mcp new
NetExec MCP
adnetwork 77 none
10d mcp zebbern/zebbern-kali-mcp new
MCP server for Kali Linux penetration testing - 121 tools for AI-assisted security testing - Giving Agents access to full pentesting tools
networkwebapprecon 47 rootcredentials
11d skill trilwu/secskills new
Transform Claude Code into your personal security engineer
redteamcode 141 rootcredentialsinstalls
12d skill SpecterOps/skills new
A marketplace for LLM skills
adbinarycodeentranetworkreconredteamsocialwebapp 622 binariesrootcredentialsinstalls
14d scanner mmaitre314/picklescan new
Security scanner detecting Python Pickle files performing suspicious actions
modfile 423 none
16d agent PurpleAILAB/Decepticon new
Autonomous Hacking Agent for Red Team
redteamnetworkwebapp 5.5k rootcredentialsinstallscalls out
18d mcp mrexodia/ida-pro-mcp new
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
binary 12k none
18d mcp PortSwigger/mcp-server new
MCP Server for Burp
webappapi 1.2k binaries
22d skill ADScanPro/Claude-AD new
Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with per-technique OPSEC/telemetry notes. Drives netexec, impacket, certipy, bloodyAD, BloodHound CE.
ad 200 root
25d scanner confident-ai/deepteam new
DeepTeam is a framework to red team LLMs and AI agents.
llmagentic 2.8k installscalls out
27d mcp mwnickerson/bloodhound_mcp new
A Model Context Protocol (MCP) server to converse with data in Bloodhound
ad 132 none
29d skill hypnguyen1209/offensive-claude new
Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest
redteamad 364 rootcredentialsinstalls
30d skill 0xSteph/pentest-ai-agents new
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
redteamrecon 2.2k rootcredentialsinstalls
32d agent bugbasesecurity/pentest-copilot new
Pentest Copilot is an AI-powered browser based ethical hacking assistant tool designed to streamline pentesting workflows.
webapp 1.5k rootcredentialsinstalls
33d agent Nightlysec/nightly new
Autonomous AI penetration testing agent
webappapicode 1 rootcredentialsinstallscalls out
43d mcp 0x4m4/hexstrike-ai new
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
webappnetworkreconbinary 12k root
44d agent NeoTheCapt/RedteamAgent new
An AI red-team agent for authorized labs and web app pentesting workflows. Turns Claude Code / OpenCode / Codex into a structured recon → test → exploit → report workflow, with containerized tools and resumable state.
webappredteam 131 credentials
63d agent GreyDGL/PentestGPT new
Automated Penetration Testing Agentic Framework Powered by Large Language Models
webappnetworkrecon 15k rootinstalls
83d agent cettocdx/rift new
RIFT - Autonomous AI Penetration Testing Agent
webappnetwork 11 binariesrootinstallscalls out
84d agent mayank-dev-15/AI-Pentest-Agent new
Autonomous AI penetration testing agent with scanning, reconnaissance, and exploitation modules
webapprecon 3 none
96d agent capture0x/AdStrike new
AI-powered modular Active Directory red-team framework for authorized penetration testing, AD enumeration, attack-path analysis, Kerberos/ADCS workflows, reporting, operator automation, and MCP server integration.
ad 353 rootcredentials
111d skill briiirussell/cybersecurity-skills new
Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex)
reconwebapp 392 root
157d agent chetstriker/LLMtary new
Autonomous AI-powered penetration testing platform. LLM-driven recon, vulnerability analysis, and exploit validation for internal & external targets. Supports local AI (Ollama, LM Studio) and cloud models (Claude, GPT-4, Gemini). Linux · macOS · Windows
reconwebapp 35 rootinstalls
160d mcp FuzzingLabs/mcp-security-hub new
A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
networkwebappbinary 786 rootcredentialsinstalls
archived agent aliasrobotics/cai new
Cybersecurity AI (CAI), the framework for AI Security
networkwebapprecon 9.8k rootcredentialsinstalls
archived mcp cyproxio/mcp-for-security new
MCP for Security: A collection of Model Context Protocol servers for popular security tools like SQLMap, FFUF, NMAP, Masscan and more. Integrate security testing and penetration testing into AI workflows.
webappnetworkrecon 630 installs
182d mcp Wh0am123/MCP-Kali-Server new
MCP configuration to connect AI agent to a Linux machine.
networkwebapp 825 root
209d scanner protectai/modelscan new
Protection against Model Serialization Attacks
modfile 774 credentials
221d scanner cyberark/FuzzyAI new
A powerful tool for automated LLM fuzzing. It is designed to help developers and security researchers identify and mitigate potential jailbreaks in their LLM APIs.
llm 1.6k none
222d mcp GH05TCREW/MetasploitMCP new
MCP Server for Metasploit
network 727 none
268d scanner mbrg/power-pwn new
An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents
cloudllm 1.2k root
288d scanner utkusen/promptmap new
a security scanner for custom LLM applications
llm 1.3k none
292d scanner splx-ai/agentic-radar new
A security scanner for your LLM agentic workflows
agentic 1.1k installs
1.2y scanner Azure/counterfit new
a CLI that provides a generic automation layer for assessing the security of ML models
llm 938 root
1.2y mcp LaurieWired/GhidraMCP new
MCP Server for Ghidra
binary 10k none
1.3y mcp MorDavid/BloodHound-MCP-AI new
BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.
ad 375 installs
1.5y mcp atomicchonk/roadrecon_mcp_server new
Claude MCP server to perform analysis on ROADrecon data
entracloud 52 none
1.6y scanner protectai/vulnhuntr new
Zero shot vulnerability discovery using LLMs
code 2.8k installs