All resources
Topic

multi-agent

8 resources across 1 kinds

Frameworks & agents

  1. pentest-aiactivehigh-risk

    An AI-driven penetration-testing tool coordinating 17 specialist agents across recon, web, API, Active Directory and cloud; findings are marked VERIFIED only after deterministic oracles re-run the exploit against the target. Ships CLI (MIT), MCP server, REST API and cloud workspace. Active, ~1.6k stars.

    Open ↗
  2. BugTraceAIactivehigh-risklicence

    A self-hosted autonomous vuln-discovery framework combining 15 specialist AI agents with real tooling in a six-phase pipeline (discovery→analysis→consolidation→exploitation→validation→reporting), with payload mutation, consensus voting, vision-based finding validation and a swarm dashboard. Python/FastAPI/React/Go, AGPL-3.0.

    Open ↗
  3. pentest-agentsactivedual-usehigh-risk

    An autonomous bug-bounty framework that orchestrates AI coding assistants (Claude Code, Codex, Gemini, Cursor, etc.) across ~50 specialized agents by vulnerability class (XSS, SQLi, CSRF, SSRF, OAuth), with a 7-Question Gate validation pipeline, bug-bounty platform integrations, payload libraries, and scope/never-submit controls.

    Open ↗
  4. Cybersecurity AI (CAI)activehigh-riskdual-use

    An open-source framework for building AI-powered offensive and defensive security automation, using ReACT-model agents with tools for command execution, web recon and code analysis, plus handoffs, swarm/hierarchical patterns, guardrails and human-in-the-loop. Supports 300+ models across providers and targets bug bounty, vulnerability discovery and exploitation workflows.

    Open ↗
  5. CVE-Factorydual-usehigh-riskcloud cost

    A multi-agent pipeline that automates end-to-end CVE reproduction: it researches CVE details, generates test cases, builds Docker environments, and validates both the exploit and the patch. It powers the LiveCVEBench evaluation and produces training traces for security-focused LLMs.

    Open ↗
  6. HPTSAactivehigh-riskdual-use

    HPTSA is a hierarchical multi-agent system from UIUC (EACL 2026) for automated web-app penetration testing, using a planning supervisor agent that coordinates specialized subagents (SQLi, XSS, CSRF, SSTI, etc.) to find and exploit vulnerabilities. Built on the OpenAI Agents SDK with GPT-4 models.

    Open ↗
  7. Claude Security (plugin)cloud costlicencepassive

    Claude Code plugin that runs a team of agents to scan a repository or diff for vulnerabilities, independently verifies each finding, and writes Markdown, JSONL and SARIF reports plus optional patch files left for review.

    Open ↗
  8. Go-based Claude Code UserPromptSubmit hook that ranks installed skills against each prompt with a local embedding index and injects the top matches as context, so long-tail skills that Claude Code would drop still surface.

    Open ↗