All resources
Topic

red-team

8 resources across 3 kinds

Tools

  1. g0 (Guard0)activedual-use

    Open-source AI agent security assessment tool that scans AI/MCP codebases with rule-based static analysis (A–F grading) and runs 3,900+ adversarial payloads for red-team testing against live agents. Also does MCP supply-chain discovery, AI-BOM generation (CycloneDX), and proxy-based runtime enforcement.

    Open ↗

Frameworks & agents

  1. Claude-BugHunteractivedual-use

    A Claude Code skill bundle for authorized security testing, providing 83 skills, 15 slash commands and pattern databases with hunt templates for 58 web vulnerability classes (XSS, SQLi, SSRF, IDOR) plus recon/OSINT and reporting workflows. Includes authorization gates and excludes internal AD, C2 and post-exploitation.

    Open ↗
  2. Pentest AI Agentsactivedual-usehigh-risk

    A set of Claude Code subagents, each a domain-specific system prompt for penetration testing, installed as agent files or a plugin, offering an advisory mode and a scope-gated mode that composes and runs tools.

    Open ↗
  3. SecSkillsdual-use

    MIT-licensed pack of 92 security skills for Claude Code in three installable plugins — offense, defense, and a shared reverse-engineering and code-audit core — encoding step-by-step methodology and judgment for red-team, DFIR, SOC, and AppSec work.

    Open ↗

References

  1. LOLC2dual-usehigh-risk

    A curated catalogue of command-and-control (C2) frameworks that abuse legitimate services (cloud APIs, messaging platforms) to evade detection, tracking abused services, open-source C2 projects, and associated detection rules with network/file/behavioral IOCs.

    Open ↗
  2. Awesome Hacking Resourcesdual-usetraining only

    A curated collection of hacking, penetration-testing, and AI red-teaming learning resources: educational courses, YouTube channels, skill-building platforms (HackTheBox, TryHackMe, CTFs), reverse-engineering/privesc/OSINT/malware-analysis training, vulnerable practice apps, exploit databases, and pentest distros (Kali, ParrotOS, BlackArch).

    Open ↗
  3. Jailbreaking Frontier Modelsactivecloud costdual-usehigh-risklicence

    Dataset of harmful-behaviour prompts (drug, chemical, biological, radiological, nuclear, explosive) and a reference PRBO reward function for training jailbreaking agents; the RL training loop is not included.

    Open ↗
  4. README-only collection of copy-paste jailbreak prompts for DeepSeek R1, Grok 3, Gemini 2.0, ChatGPT (DAN), Claude 2 and Llama 2, plus a Gemini system-prompt leak prompt, mostly reposted from linked Reddit, blog and GitHub posts.

    Open ↗