trailofbits/fickling
- Licence
- LGPL
- Maintainers
- 23 contributors · top author wrote 26%
- Size
- 9,573 lines · 46 code files · tests, CI, lockfile
- Bundled tools
- none found
- Shares files with
- no overlap found
Before running it
Ships compiled binaries you did not build
no
Asks for root or sudo
no
Reads credential paths such as ~/.aws or ~/.ssh
yes
Installs software on your host
yes
Calls an endpoint the project does not own
no
Contains long encoded blobs you cannot read
yes
scanner
| Last updated | Category | Tool | Scope | Stars | Flags |
|---|---|---|---|---|---|
| ★ today | scanner |
Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.
|
llmagentic | 25k | rootcredentialsinstallscalls outopaque |
| ★ today | scanner |
Security scanner for AI agents, MCP servers and agent skills.
|
agentic | 3.0k | rootcredentialsinstalls |
| ★ today | scanner |
A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
|
llmagentic | 6.4k | rootcredentialsinstallscalls out |
| ★ today | scanner |
Static security scanner for ML model files — detects pickle bombs, Keras Lambda RCE and GGUF template injection, and generates CycloneDX / SPDX AI-BOMs (AIBOM) as EU AI Act, CRA and FDA §524B evidence.
|
modfile | 77 | none |
| ★ today | scanner |
Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment
|
modfile | 70 | rootcredentialscalls out |
| ★ 1d | scanner |
The Python Risk Identification Tool for generative AI (PyRIT) is an open source framework built to empower security professionals and engineers to proactively identify risks in generative AI systems.
|
llm | 4.5k | rootinstallscalls outopaque |
| ★ 1d | scanner |
Scan MCP servers for potential threats & security findings.
|
agentic | 1.1k | rootcredentials |
| ★ 3d | scanner |
Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.
|
agentic | 434 | rootcredentialsinstalls |
| ★ 4d | scanner |
Agentic LLM Vulnerability Scanner / AI red teaming kit 🧪
|
llmagentic | 2.0k | calls out |
| ★ 5d | scanner |
A Python pickling decompiler and static analyzer
|
modfile | 668 | credentialsinstallsopaque |
| ★ 6d | scanner |
the LLM vulnerability scanner
|
llm | 9.2k | root |
| ★ 14d | scanner |
Security scanner detecting Python Pickle files performing suspicious actions
|
modfile | 423 | none |
| ★ 25d | scanner |
DeepTeam is a framework to red team LLMs and AI agents.
|
llmagentic | 2.8k | installscalls out |
| 209d | scanner |
Protection against Model Serialization Attacks
|
modfile | 774 | credentials |
| 221d | scanner |
A powerful tool for automated LLM fuzzing. It is designed to help developers and security researchers identify and mitigate potential jailbreaks in their LLM APIs.
|
llm | 1.6k | none |
| 268d | scanner |
An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents
|
cloudllm | 1.2k | root |
| 288d | scanner |
a security scanner for custom LLM applications
|
llm | 1.3k | none |
| 292d | scanner |
A security scanner for your LLM agentic workflows
|
agentic | 1.1k | installs |
| 1.2y | scanner |
a CLI that provides a generic automation layer for assessing the security of ML models
|
llm | 938 | root |
| 1.6y | scanner |
Zero shot vulnerability discovery using LLMs
|
code | 2.8k | installs |