Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
-
Updated
Oct 2, 2026 - Python
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
Open-source AI-powered offensive security harness for automated penetration testing.
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.
NeuroSploit is an advanced, AI-powered penetration testing framework designed to automate and augment various aspects of offensive security operations.
Open-source autonomous AI penetration testing. 50 specialist agents across web, API, cloud, Active Directory, Kubernetes, CI/CD and AI/LLM (OWASP LLM Top 10). Runs on a local LLM behind a Privacy Gateway. Integrates with GitHub, GitLab, Jenkins, VS Code, JetBrains, n8n, Grafana & Splunk.
Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model.
Autonomous AI-powered security scanning platform — CLI scanner, web dashboard, and one-command Docker deployment
Cyberful is an open-source AI Red Team for discovering, exploiting, verifying, and remediating vulnerabilities.
Shannon-Uncontained. A Docker-free, black‑box‑first fork that treats AI as a fallible witness rather than an oracle: treats uncertainty as a first class citizen via EQBSL epistemic bookkeeping, and agentic recon/analysis/synthesis tuned for “paste url -> pwn box -> ???? -> profit”
A local proxy that keeps client data out of Claude Code.
open-source pentest management built to be operated by an AI agent
The autonomous pentester that proves its findings — AI-driven, evidence-first, behind-login.
Open-source AI security tool to scan and fix vulnerabilities in your vibe-coded projects before you ship. AXguard by AwareXone.
The security engine of your Agentic Company
Mergen is an MCP server that gives your AI a real red team brain. It doesn't just run tools, it picks the right ones, chains them together, and actually makes sense of the output. Built by pentesters, for pentesters who are tired of babysitting scripts.
Semantic Stealth Attacks & Symbolic Prompt Red Teaming on GPT and other LLMs.
Zentra is an open source CLI agent harness tool designed to assist with SAST and DAST on your application
To associate your repository with the ai-penetration-testing topic, visit your repo's landing page and select "manage topics."