Frameworks & agents
AI-driven and multi-agent security frameworks to study or run.
- Open ↗
AI-driven autonomous penetration-testing framework: an MCP server that lets an external LLM drive ~90+ offensive binaries plus native decision-engine, CVE-intelligence, and fault-tolerance subsystems.
- Open ↗PentestGPTplanner-executor
Task-tree and planner/executor pentest reference architecture; local models supported mainly in its human-guided workflow.
- Open ↗
An AI-driven penetration-testing tool coordinating 17 specialist agents across recon, web, API, Active Directory and cloud; findings are marked VERIFIED only after deterministic oracles re-run the exploit against the target. Ships CLI (MIT), MCP server, REST API and cloud workspace. Active, ~1.6k stars.
- Open ↗
A self-hosted autonomous vuln-discovery framework combining 15 specialist AI agents with real tooling in a six-phase pipeline (discovery→analysis→consolidation→exploitation→validation→reporting), with payload mutation, consensus voting, vision-based finding validation and a swarm dashboard. Python/FastAPI/React/Go, AGPL-3.0.
- Open ↗
An autonomous bug-bounty framework that orchestrates AI coding assistants (Claude Code, Codex, Gemini, Cursor, etc.) across ~50 specialized agents by vulnerability class (XSS, SQLi, CSRF, SSRF, OAuth), with a 7-Question Gate validation pipeline, bug-bounty platform integrations, payload libraries, and scope/never-submit controls.
- Open ↗Vul-RAG (KnowledgeRAG4LLMVulD)source-analysis
Vul-RAG, a knowledge-level retrieval-augmented-generation framework for LLM-based vulnerability detection: it extracts vulnerability knowledge from CVEs into a knowledge base and uses it to judge whether given code is vulnerable. Ships the LinuxVul benchmark (4,667 vulnerable/patched function pairs from 2,174 Linux-kernel CVEs across the top-10 CWEs); the authors report finding 10 previously-unknown kernel bugs, 6 receiving CVE assignments.
- Open ↗JudgeZoollm-red-teaming
A Python library providing standardized, tested implementations of 15+ LLM safety judges (StrongREJECT, LlamaGuard, WildGuard, HarmBench, and others) behind a unified API. Returns a normalized 0-1 harm score (p_harmful) for LLM conversations, supports both local fine-tuned and remote foundation-model judges, and warns when a setup diverges from the original implementation to preserve reproducibility.
- Open ↗
A research framework that trains custom LLMs (Qwen 14B with reinforcement learning) on curated penetration-testing reasoning datasets to autonomously generate pentest strategies and step-by-step actions. Ships dataset-collection utilities, training code, RL experiments, and CTF-based evaluation, with an accompanying arXiv preprint.
- Open ↗Project ZySecsecurity-copilot
An AI security co-pilot built on the open ZySec 7B model, trained across 30+ cybersecurity domains, providing threat analysis, playbook/document retrieval and standards reference for security professionals. Runs locally (CPU or GPU via vLLM) through a Streamlit UI and is OpenAI-API compatible.
- Open ↗
An open-source framework for building AI-powered offensive and defensive security automation, using ReACT-model agents with tools for command execution, web recon and code analysis, plus handoffs, swarm/hierarchical patterns, guardrails and human-in-the-loop. Supports 300+ models across providers and targets bug bounty, vulnerability discovery and exploitation workflows.
- Open ↗
A Claude Code skill bundle for authorized security testing, providing 83 skills, 15 slash commands and pattern databases with hunt templates for 58 web vulnerability classes (XSS, SQLi, SSRF, IDOR) plus recon/OSINT and reporting workflows. Includes authorization gates and excludes internal AD, C2 and post-exploitation.
- Open ↗
Academic (TU Wien ipa-lab) open-source framework for building LLM-driven autonomous pentest agents in under ~50 lines, covering Linux privilege escalation, web-app and REST-API testing via SSH/local shell. Includes SQLite run logging and a web viewer for replaying agent runs; supports OpenAI and local models.
- Open ↗WhiteRabbitNeo-PentestGPTplanner-executor
Open-source pentest assistant that pairs the WhiteRabbitNeo security LLM with the PentestGPT prompting methodology, using structured todo-list workflows and constrained (outlines) generation to keep the fully-open-source stack usable without proprietary APIs. Author notes parity with GPT-4 is still a work in progress.
- Open ↗
A multi-agent pipeline that automates end-to-end CVE reproduction: it researches CVE details, generates test cases, builds Docker environments, and validates both the exploit and the patch. It powers the LiveCVEBench evaluation and produces training traces for security-focused LLMs.
- Open ↗
An AI-powered bug bounty toolkit (standalone CLI and Claude Code plugin) that runs an autonomous scope-to-report loop: recon, hunting across 26+ web vulnerability classes and smart-contract bug categories, a validation gate, and submission-ready reports for HackerOne, Bugcrowd, Intigriti, and Immunefi. Orchestrates ~35 external scanners and supports Ollama/Groq or paid AI providers.
- Open ↗
HPTSA is a hierarchical multi-agent system from UIUC (EACL 2026) for automated web-app penetration testing, using a planning supervisor agent that coordinates specialized subagents (SQLi, XSS, CSRF, SSTI, etc.) to find and exploit vulnerabilities. Built on the OpenAI Agents SDK with GPT-4 models.
- Open ↗
An LLM-powered agent (built on CrewAI) that automates Google Dorking for reconnaissance in penetration testing and bug bounty. It generates and refines dork queries with an LLM (OpenAI, Anthropic, or Gemini), analyzes results, and produces structured vulnerability reports to surface information disclosure, misconfigurations, and exposed sensitive data.
- Open ↗
Kali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.
- Open ↗
Apache-2.0 library of 818 agentskills.io-format cybersecurity skills in 34 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, ATLAS, D3FEND, NIST AI RMF and F3, for loading into Claude Code, Codex CLI, Cursor and similar agents.
- Open ↗
MIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.
- Open ↗
Claude Code plugin marketplace of 45 installable plugins (110 skills) covering pentest, threat modeling, detection engineering, DFIR, GRC and LLM/agentic-AI security, with role bundles such as pentester that auto-install their parts.
- Open ↗
Archived Claude Code feature plugin that used hooks to detect friction signals (user corrections, tool failures, tone escalation) and propose CLAUDE.md rule updates; retired in favour of netresearch/retro-skill.
- Open ↗Claude Code Infrastructure Showcaseagent-workflow-tooling
MIT reference library of Claude Code hooks, 4 skills, 8 agents and 4 slash commands with a setup wizard, for auto-activating skills from prompts and file context in coding sessions; general agent tooling, not security-specific.
- Open ↗
Claude Code skill pack wrapping Ghidra, YARA, CAPA, Frida, FakeNet and an 18-service threat-intel client behind Docker and VMware isolation, for static, dynamic and web-forensic malware analysis on Windows.
- Open ↗Claude Reflectagent-workflow-tooling
MIT-licensed Claude Code plugin whose hooks queue your corrections and 'remember:' notes, then on /reflect review and sync them into CLAUDE.md, AGENTS.md and skill files; it also mines session history for repeatable commands.
- Open ↗
Claude Code skill pack whose /reflect command turns a session's corrections into permanent edits to local skill files, with timestamped backups and git commits, so the assistant stops repeating the same mistakes.
- Open ↗
Claude Code plugin that runs a team of agents to scan a repository or diff for vulnerabilities, independently verifies each finding, and writes Markdown, JSONL and SARIF reports plus optional patch files left for review.
- Open ↗Claude Skills MCP Serveragent-workflow-tooling
Apache-2.0 MCP server, now unmaintained, that semantically searches and progressively loads Anthropic Agent Skills (official and scientific sets by default) into any MCP-compatible coding assistant; not security-specific.
- Open ↗claude-adhd-skillsagent-workflow-tooling
MIT-licensed Claude Code skills and hooks for staying organized when working with AI agents: a date-injection hook, timed nudge reminders, Obsidian daily-journal and vault-management skills, and a CLAUDE.md template.
- Open ↗
Claude Code plugin that retrofits an existing skill or agent with a @BOOT/@REVIEW/@EVOLVE feedback loop, recording learned patterns to a feedback/ directory and asking for approval before each change.
- Open ↗GoldenWing Security Skillsagent-security-skills
Pack of 38 defensive-only Markdown skills for Claude Code and compatible coding agents, covering MCP security, prompt-injection defense, OWASP LLM Top 10, VPS/WordPress/Cloudflare hardening and incident response.
- Open ↗
Agent skills for Claude Code, Gemini CLI or other Skills/MCP agents that analyze mitmproxy-captured traffic for vulnerability classes such as IDOR, SSRF, SQLi, auth and secrets, distilled from disclosed HackerOne bug bounty reports.
- Open ↗Meta-Routeragent-workflow-tooling
Go-based Claude Code UserPromptSubmit hook that ranks installed skills against each prompt with a local embedding index and injects the top matches as context, so long-tail skills that Claude Code would drop still surface.
- Open ↗
A set of Claude Code subagents, each a domain-specific system prompt for penetration testing, installed as agent files or a plugin, offering an advisory mode and a scope-gated mode that composes and runs tools.
- Open ↗
Six Claude Code plugins (27 skills, MIT) for pre-merge security review, STRIDE threat modelling, opengrep/semgrep rule generation, tiered CTI search across 595 curated domains, and security-first PRD writing.
- Open ↗Reverse Engineering Skills (hackersifu)agent-security-skills
Agent skills for defensive malware analysis (re-ioc-extraction and re-unpacker), shipped for both Claude Code and OpenAI Codex, for evidence-first IOC extraction and static-first unpacking plans.
- Open ↗
Claude Code plugin that hooks Edit/Write, end-of-turn, and git commit to flag ~25 dangerous code patterns and run LLM diff reviews for injection, XSS, SSRF, IDOR, and hardcoded secrets in generated code.
- Open ↗
MIT Claude Code plugin (with Codex, Cowork and ChatGPT Work variants) porting Hermes Agent's learning loop: hooks detect complex work, a background session distills it into SKILL.md files, a curator archives stale ones.
- Open ↗Self-Improving Skills (unisone)agent-workflow-tooling
Claude Code plugin of shell hooks and slash commands that logs skill invocations and outcomes, audits skill health, applies backed-up amendments, and checks pre/post metrics to verify the fix.
- Open ↗
Agent-Skills pack for AI coding agents, generated largely from open-source Semgrep rules: secure-coding guidance across 15+ languages, OWASP LLM Top 10 (2025) guidance, and Semgrep scanning plus custom-rule authoring.
- Open ↗
Skill-governance plugin for Claude Code, Codex, Command Code, Oh My Pi, ZCode, DeepSeek Harness and Cline: semantic skill retrieval, a per-turn use-mandate hook and an append-only invocation ledger, so the agent picks and uses the fitting skill.
- Open ↗Superpowersagent-workflow-tooling
MIT-licensed skill pack and development methodology for coding agents (Claude Code, Codex, Cursor and others) covering brainstorming, planning, TDD, code review and subagent-driven implementation; not security-specific.
- Open ↗
Settings template, blocking hooks, path-scoped language rules, slash commands and an MCP template for Claude Code, with notes on sandboxing bypass-permissions runs, local models and context management.
- Open ↗Trail of Bits Skillsagent-security-skills
A Claude Code plugin marketplace of security-analysis, testing and development skills — smart-contract vulnerability scanners, C/C++ and Rust security code review, Semgrep and YARA rule authoring, constant-time and zeroization checks — loadable in Claude Code, Codex or a ChatGPT workspace.
- Open ↗
MIT-licensed Python package of 37 typed-decision runners for the paid TypeSafe Jev API, including seven SOC agents that recommend triage, containment and escalation for the caller to run, and three that screen prompts and drafts.
- Open ↗
MIT-licensed research-stage harness in which an LLM proposes one read or patch, code validates it, Jev answers four yes/no questions, and a fixed table decides; the host owns authorization, and nothing is applied or executed.