All resources
Topic

ai-agent

20 resources across 3 kinds

Tools

  1. A Burp Suite extension (formerly Burp AI Agent) that integrates AI into web security testing: connects to 11 AI providers (Ollama, Claude, Gemini, OpenAI-compatible), exposes up to 59 MCP tools for external AI clients to drive Burp, includes passive/active scanners covering 62 vulnerability classes, and offers privacy modes with host anonymization and AES-256-GCM credential storage.

    Open ↗
  2. MIT-licensed MCP server that gives AI agents access to CrowdStrike Falcon — detections, threat intel, hosts, vulnerabilities, NG-SIEM queries — with a read-only mode and tool allow/deny lists; needs Falcon API credentials.

    Open ↗
  3. Ghidra RPCdual-uselicencepassive

    Agent skill plus CLI daemon that keeps Ghidra warm in-process via PyGhidra and returns JSON, so any shell-capable coding assistant can decompile, navigate, annotate, retype, patch and diff binaries without a human in the loop.

    Open ↗
  4. agent-chaperonecloud costhosted

    Apache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.

    Open ↗
  5. dsh-jev-interceptorcloud costhostedopt-in

    MIT-licensed DeepSeek Harness plugin that scores non-read-only tool calls for risk, irreversibility and injection suspicion with TypeSafe's hosted Jev model, escalating or denying only in enforce mode; needs a paid API key.

    Open ↗
  6. Jev Sentinelcloud costhosted

    MIT-licensed guard for coding agents (a Pi extension and Claude Code/Codex CLI plugins) that scores tool calls, outputs and replies with TypeSafe's Jev for injection and risk, then allows, asks, or blocks; needs a TypeSafe key.

    Open ↗
  7. jev-guardcloud costhosted

    MIT-licensed hook for seven coding agents and any ACP pair that asks TypeSafe's hosted Jev typed questions about a tool call or its result, then denies, asks or allows it and flags suspected prompt injection; needs a billed key.

    Open ↗
  8. jevkit (Jev Agent Kit)cloud costhosted

    MIT-licensed CLI and MCP server giving agents eleven typed-decision tools on TypeSafe's hosted Jev model (route, triage, guard, grep, rank, compact), plus an advisory Claude Code PreToolUse hook; needs a TypeSafe API key.

    Open ↗

Frameworks & agents

  1. BugHunteractivedual-usehigh-risk

    An AI-powered bug bounty toolkit (standalone CLI and Claude Code plugin) that runs an autonomous scope-to-report loop: recon, hunting across 26+ web vulnerability classes and smart-contract bug categories, a validation gate, and submission-ready reports for HackerOne, Bugcrowd, Intigriti, and Immunefi. Orchestrates ~35 external scanners and supports Ollama/Groq or paid AI providers.

    Open ↗
  2. Agentic Malware Analysiscloud costhigh-risk

    Kali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.

    Open ↗
  3. MIT reference library of Claude Code hooks, 4 skills, 8 agents and 4 slash commands with a setup wizard, for auto-activating skills from prompts and file context in coding sessions; general agent tooling, not security-specific.

    Open ↗
  4. Apache-2.0 MCP server, now unmaintained, that semantically searches and progressively loads Anthropic Agent Skills (official and scientific sets by default) into any MCP-compatible coding assistant; not security-specific.

    Open ↗
  5. Pentest AI Agentsactivedual-usehigh-risk

    A set of Claude Code subagents, each a domain-specific system prompt for penetration testing, installed as agent files or a plugin, offering an advisory mode and a scope-gated mode that composes and runs tools.

    Open ↗
  6. Skill-governance plugin for Claude Code, Codex, Command Code, Oh My Pi, ZCode, DeepSeek Harness and Cline: semantic skill retrieval, a per-turn use-mandate hook and an append-only invocation ledger, so the agent picks and uses the fitting skill.

    Open ↗
  7. MIT-licensed skill pack and development methodology for coding agents (Claude Code, Codex, Cursor and others) covering brainstorming, planning, TDD, code review and subagent-driven implementation; not security-specific.

    Open ↗
  8. Settings template, blocking hooks, path-scoped language rules, slash commands and an MCP template for Claude Code, with notes on sandboxing bypass-permissions runs, local models and context management.

    Open ↗
  9. Jev Use Casescloud cost

    MIT-licensed Python package of 37 typed-decision runners for the paid TypeSafe Jev API, including seven SOC agents that recommend triage, containment and escalation for the caller to run, and three that screen prompts and drafts.

    Open ↗
  10. jev-harnesscloud costopt-in

    MIT-licensed research-stage harness in which an LLM proposes one read or patch, code validates it, Jev answers four yes/no questions, and a fixed table decides; the host owns authorization, and nothing is applied or executed.

    Open ↗

References

  1. AboutSecurity (WgpSec)dual-usehigh-risk

    A structured penetration-testing knowledge base by the WgpSec team, packaged for consumption by AI agents: 200+ attack-chain methodologies (recon through post-exploitation, cloud, code audit, CTF, malware analysis, lateral movement), password/fuzzing dictionaries, exploit payloads for SQLi/XSS/SSRF, and a 600+ entry vulnerability database organized by product. It is the knowledge layer of the WgpSec agentic pentest ecosystem (MCP server + autonomous agent).

    Open ↗
  2. MIT-licensed curated index of 225+ general-purpose AI tools (chat, coding, research, image, video, voice, agents, local model runners) with a per-tool writeup page; a general AI directory with no security-specific content.

    Open ↗