All resources

Frameworks & agents

AI-driven and multi-agent security frameworks to study or run.

54 shown
  1. Arm Metiswhite-box-sast

    Apache-2.0 white-box framework with broad language support, local-model support, deterministic evidence collection, and validation of SAST findings.

    Open ↗
  2. HexStrike AIai-offensive-orchestratordual-use

    AI-driven autonomous penetration-testing framework: an MCP server that lets an external LLM drive ~90+ offensive binaries plus native decision-engine, CVE-intelligence, and fault-tolerance subsystems.

    Open ↗
  3. PentAGImulti-agent-pentest

    Autonomous pentest framework with multi-agent roles, Docker isolation, memory, observability, and native GLM/Ollama/custom OpenAI-compatible provider support.

    Open ↗
  4. PentestGPTplanner-executor

    Task-tree and planner/executor pentest reference architecture; local models supported mainly in its human-guided workflow.

    Open ↗
  5. PyRITllm-red-teaming

    Python Risk Identification Tool for generative AI — a framework for automating red-team assessments of LLM systems; named alongside garak.

    Open ↗
  6. Strixweb-pentest

    Apache-2.0 web-pentesting agent framework with browser automation, HTTP interception, terminal tools, code analysis, multi-agent orchestration, validation, and reporting.

    Open ↗
  7. Vulnhuntrsource-analysis

    Protect AI tool for finding vulnerabilities in Python source-available targets; authors note difficulty getting reliable structured output from current local/open models.

    Open ↗
  8. pentest-aimulti-agent-pentestactivehigh-risk

    An AI-driven penetration-testing tool coordinating 17 specialist agents across recon, web, API, Active Directory and cloud; findings are marked VERIFIED only after deterministic oracles re-run the exploit against the target. Ships CLI (MIT), MCP server, REST API and cloud workspace. Active, ~1.6k stars.

    Open ↗
  9. BugTraceAImulti-agent-pentestactivehigh-risklicence

    A self-hosted autonomous vuln-discovery framework combining 15 specialist AI agents with real tooling in a six-phase pipeline (discovery→analysis→consolidation→exploitation→validation→reporting), with payload mutation, consensus voting, vision-based finding validation and a swarm dashboard. Python/FastAPI/React/Go, AGPL-3.0.

    Open ↗
  10. pentest-agentsmulti-agent-pentestactivedual-usehigh-risk

    An autonomous bug-bounty framework that orchestrates AI coding assistants (Claude Code, Codex, Gemini, Cursor, etc.) across ~50 specialized agents by vulnerability class (XSS, SQLi, CSRF, SSRF, OAuth), with a 7-Question Gate validation pipeline, bug-bounty platform integrations, payload libraries, and scope/never-submit controls.

    Open ↗
  11. Vul-RAG, a knowledge-level retrieval-augmented-generation framework for LLM-based vulnerability detection: it extracts vulnerability knowledge from CVEs into a knowledge base and uses it to judge whether given code is vulnerable. Ships the LinuxVul benchmark (4,667 vulnerable/patched function pairs from 2,174 Linux-kernel CVEs across the top-10 CWEs); the authors report finding 10 previously-unknown kernel bugs, 6 receiving CVE assignments.

    Open ↗
  12. JudgeZoollm-red-teaming

    A Python library providing standardized, tested implementations of 15+ LLM safety judges (StrongREJECT, LlamaGuard, WildGuard, HarmBench, and others) behind a unified API. Returns a normalized 0-1 harm score (p_harmful) for LLM conversations, supports both local fine-tuned and remote foundation-model judges, and warns when a setup diverges from the original implementation to preserve reproducibility.

    Open ↗
  13. Pentest-Strategistplanner-executortraining only

    A research framework that trains custom LLMs (Qwen 14B with reinforcement learning) on curated penetration-testing reasoning datasets to autonomously generate pentest strategies and step-by-step actions. Ships dataset-collection utilities, training code, RL experiments, and CTF-based evaluation, with an accompanying arXiv preprint.

    Open ↗
  14. Project ZySecsecurity-copilot

    An AI security co-pilot built on the open ZySec 7B model, trained across 30+ cybersecurity domains, providing threat analysis, playbook/document retrieval and standards reference for security professionals. Runs locally (CPU or GPU via vLLM) through a Streamlit UI and is OpenAI-API compatible.

    Open ↗
  15. Cybersecurity AI (CAI)ai-offensive-orchestratoractivehigh-riskdual-use

    An open-source framework for building AI-powered offensive and defensive security automation, using ReACT-model agents with tools for command execution, web recon and code analysis, plus handoffs, swarm/hierarchical patterns, guardrails and human-in-the-loop. Supports 300+ models across providers and targets bug bounty, vulnerability discovery and exploitation workflows.

    Open ↗
  16. Claude-BugHunterai-offensive-orchestratoractivedual-use

    A Claude Code skill bundle for authorized security testing, providing 83 skills, 15 slash commands and pattern databases with hunt templates for 58 web vulnerability classes (XSS, SQLi, SSRF, IDOR) plus recon/OSINT and reporting workflows. Includes authorization gates and excludes internal AD, C2 and post-exploitation.

    Open ↗
  17. hackingBuddyGPTai-offensive-orchestratoractive

    Academic (TU Wien ipa-lab) open-source framework for building LLM-driven autonomous pentest agents in under ~50 lines, covering Linux privilege escalation, web-app and REST-API testing via SSH/local shell. Includes SQLite run logging and a web viewer for replaying agent runs; supports OpenAI and local models.

    Open ↗
  18. Open-source pentest assistant that pairs the WhiteRabbitNeo security LLM with the PentestGPT prompting methodology, using structured todo-list workflows and constrained (outlines) generation to keep the fully-open-source stack usable without proprietary APIs. Author notes parity with GPT-4 is still a work in progress.

    Open ↗
  19. CVE-Factoryai-offensive-orchestratordual-usehigh-riskcloud cost

    A multi-agent pipeline that automates end-to-end CVE reproduction: it researches CVE details, generates test cases, builds Docker environments, and validates both the exploit and the patch. It powers the LiveCVEBench evaluation and produces training traces for security-focused LLMs.

    Open ↗
  20. BugHunterai-offensive-orchestratoractivedual-usehigh-risk

    An AI-powered bug bounty toolkit (standalone CLI and Claude Code plugin) that runs an autonomous scope-to-report loop: recon, hunting across 26+ web vulnerability classes and smart-contract bug categories, a validation gate, and submission-ready reports for HackerOne, Bugcrowd, Intigriti, and Immunefi. Orchestrates ~35 external scanners and supports Ollama/Groq or paid AI providers.

    Open ↗
  21. HPTSAmulti-agent-pentestactivehigh-riskdual-use

    HPTSA is a hierarchical multi-agent system from UIUC (EACL 2026) for automated web-app penetration testing, using a planning supervisor agent that coordinates specialized subagents (SQLi, XSS, CSRF, SSTI, etc.) to find and exploit vulnerabilities. Built on the OpenAI Agents SDK with GPT-4 models.

    Open ↗
  22. DorkAgentai-offensive-orchestratorpassiveopt-in

    An LLM-powered agent (built on CrewAI) that automates Google Dorking for reconnaissance in penetration testing and bug bounty. It generates and refines dork queries with an LLM (OpenAI, Anthropic, or Gemini), analyzes results, and produces structured vulnerability reports to surface information disclosure, misconfigurations, and exposed sensitive data.

    Open ↗
  23. Langfusellm-observability

    Open-source LLM engineering platform for tracing, evaluation, prompt management, and metrics — instrument an AI application's calls end to end to debug, measure, and monitor model behavior in development and production.

    Open ↗
  24. Agentic Malware Analysisagent-security-skillscloud costhigh-risk

    Kali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.

    Open ↗
  25. Anthropic Cybersecurity Skillsagent-security-skillsdual-use

    Apache-2.0 library of 818 agentskills.io-format cybersecurity skills in 34 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, ATLAS, D3FEND, NIST AI RMF and F3, for loading into Claude Code, Codex CLI, Cursor and similar agents.

    Open ↗
  26. AppSec (florianbuetow)agent-security-skillspassive

    MIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.

    Open ↗
  27. Awesome Claude Securityagent-security-skillsdual-use

    Claude Code plugin marketplace of 45 installable plugins (110 skills) covering pentest, threat modeling, detection engineering, DFIR, GRC and LLM/agentic-AI security, with role bundles such as pentester that auto-install their parts.

    Open ↗
  28. Claude Coach (archived)agent-workflow-toolinglicence

    Archived Claude Code feature plugin that used hooks to detect friction signals (user corrections, tool failures, tone escalation) and propose CLAUDE.md rule updates; retired in favour of netresearch/retro-skill.

    Open ↗
  29. MIT reference library of Claude Code hooks, 4 skills, 8 agents and 4 slash commands with a setup wizard, for auto-activating skills from prompts and file context in coding sessions; general agent tooling, not security-specific.

    Open ↗
  30. Claude Code RE Toolkitagent-security-skillsactivehigh-risk

    Claude Code skill pack wrapping Ghidra, YARA, CAPA, Frida, FakeNet and an 18-service threat-intel client behind Docker and VMware isolation, for static, dynamic and web-forensic malware analysis on Windows.

    Open ↗
  31. Claude Reflectagent-workflow-tooling

    MIT-licensed Claude Code plugin whose hooks queue your corrections and 'remember:' notes, then on /reflect review and sync them into CLAUDE.md, AGENTS.md and skill files; it also mines session history for repeatable commands.

    Open ↗
  32. Claude Reflect System (haddock)agent-workflow-toolinglicence

    Claude Code skill pack whose /reflect command turns a session's corrections into permanent edits to local skill files, with timestamped backups and git commits, so the assistant stops repeating the same mistakes.

    Open ↗
  33. Claude Security (plugin)agent-security-skillscloud costlicencepassive

    Claude Code plugin that runs a team of agents to scan a repository or diff for vulnerabilities, independently verifies each finding, and writes Markdown, JSONL and SARIF reports plus optional patch files left for review.

    Open ↗
  34. Claude Skills MCP Serveragent-workflow-tooling

    Apache-2.0 MCP server, now unmaintained, that semantically searches and progressively loads Anthropic Agent Skills (official and scientific sets by default) into any MCP-compatible coding assistant; not security-specific.

    Open ↗
  35. claude-adhd-skillsagent-workflow-tooling

    MIT-licensed Claude Code skills and hooks for staying organized when working with AI agents: a date-injection hook, timed nudge reminders, Obsidian daily-journal and vault-management skills, and a CLAUDE.md template.

    Open ↗
  36. Feedback Loop Builderagent-workflow-toolinglicence

    Claude Code plugin that retrofits an existing skill or agent with a @BOOT/@REVIEW/@EVOLVE feedback loop, recording learned patterns to a feedback/ directory and asking for approval before each change.

    Open ↗
  37. GoldenWing Security Skillsagent-security-skills

    Pack of 38 defensive-only Markdown skills for Claude Code and compatible coding agents, covering MCP security, prompt-injection defense, OWASP LLM Top 10, VPS/WordPress/Cloudflare hardening and incident response.

    Open ↗
  38. InstaVM Security Skillsagent-security-skillsdual-uselicence

    Agent skills for Claude Code, Gemini CLI or other Skills/MCP agents that analyze mitmproxy-captured traffic for vulnerability classes such as IDOR, SSRF, SQLi, auth and secrets, distilled from disclosed HackerOne bug bounty reports.

    Open ↗
  39. Meta-Routeragent-workflow-tooling

    Go-based Claude Code UserPromptSubmit hook that ranks installed skills against each prompt with a local embedding index and injects the top matches as context, so long-tail skills that Claude Code would drop still surface.

    Open ↗
  40. Pentest AI Agentsagent-security-skillsactivedual-usehigh-risk

    A set of Claude Code subagents, each a domain-specific system prompt for penetration testing, installed as agent files or a plugin, offering an advisory mode and a scope-gated mode that composes and runs tools.

    Open ↗
  41. Phoenix Security Skillsagent-security-skillscloud cost

    Six Claude Code plugins (27 skills, MIT) for pre-merge security review, STRIDE threat modelling, opengrep/semgrep rule generation, tiered CTI search across 595 curated domains, and security-first PRD writing.

    Open ↗
  42. Agent skills for defensive malware analysis (re-ioc-extraction and re-unpacker), shipped for both Claude Code and OpenAI Codex, for evidence-first IOC extraction and static-first unpacking plans.

    Open ↗
  43. SecSkillsagent-security-skillsdual-use

    MIT-licensed pack of 92 security skills for Claude Code in three installable plugins — offense, defense, and a shared reverse-engineering and code-audit core — encoding step-by-step methodology and judgment for red-team, DFIR, SOC, and AppSec work.

    Open ↗
  44. Security Guidance (Claude Code plugin)agent-security-skillscloud costlicence

    Claude Code plugin that hooks Edit/Write, end-of-turn, and git commit to flag ~25 dangerous code patterns and run LLM diff reviews for injection, XSS, SSRF, IDOR, and hardcoded secrets in generated code.

    Open ↗
  45. Self-Improving Skills (UniM0cha)agent-workflow-toolingcloud costhigh-risk

    MIT Claude Code plugin (with Codex, Cowork and ChatGPT Work variants) porting Hermes Agent's learning loop: hooks detect complex work, a background session distills it into SKILL.md files, a curator archives stale ones.

    Open ↗
  46. Self-Improving Skills (unisone)agent-workflow-tooling

    Claude Code plugin of shell hooks and slash commands that logs skill invocations and outcomes, audits skill health, applies backed-up amendments, and checks pre/post metrics to verify the fix.

    Open ↗
  47. Semgrep Agent Skillsagent-security-skillslicence

    Agent-Skills pack for AI coding agents, generated largely from open-source Semgrep rules: secure-coding guidance across 15+ languages, OWASP LLM Top 10 (2025) guidance, and Semgrep scanning plus custom-rule authoring.

    Open ↗
  48. Skill Conciergeagent-workflow-toolinglicence

    Skill-governance plugin for Claude Code, Codex, Command Code, Oh My Pi, ZCode, DeepSeek Harness and Cline: semantic skill retrieval, a per-turn use-mandate hook and an append-only invocation ledger, so the agent picks and uses the fitting skill.

    Open ↗
  49. Stop Slopagent-workflow-toolingpassive

    MIT-licensed skill file with phrase, structure and example references that teaches Claude or any LLM to strip recognisable AI-writing patterns from prose, with a five-dimension 1-10 scoring rubric; a writing aid, not a security tool.

    Open ↗
  50. Superpowersagent-workflow-tooling

    MIT-licensed skill pack and development methodology for coding agents (Claude Code, Codex, Cursor and others) covering brainstorming, planning, TDD, code review and subagent-driven implementation; not security-specific.

    Open ↗
  51. Trail of Bits Claude Code Configagent-workflow-toolinglicence

    Settings template, blocking hooks, path-scoped language rules, slash commands and an MCP template for Claude Code, with notes on sandboxing bypass-permissions runs, local models and context management.

    Open ↗
  52. Trail of Bits Skillsagent-security-skills

    A Claude Code plugin marketplace of security-analysis, testing and development skills — smart-contract vulnerability scanners, C/C++ and Rust security code review, Semgrep and YARA rule authoring, constant-time and zeroization checks — loadable in Claude Code, Codex or a ChatGPT workspace.

    Open ↗
  53. Jev Use Casessecurity-copilotcloud cost

    MIT-licensed Python package of 37 typed-decision runners for the paid TypeSafe Jev API, including seven SOC agents that recommend triage, containment and escalation for the caller to run, and three that screen prompts and drafts.

    Open ↗
  54. jev-harnessagent-workflow-toolingcloud costopt-in

    MIT-licensed research-stage harness in which an LLM proposes one read or patch, code validates it, Jev answers four yes/no questions, and a fixed table decides; the host owns authorization, and nothing is applied or executed.

    Open ↗