pwnsy

Trending Security Repos

1
Oldcircle/geo‑sleuth

An agent skill that finds where a photo was taken — OpenStreetMap geometry, elevation skylines, satellite imagery and street view — and shows its work. Works with Claude Code, Codex, Cursor, Gemini CLI, OpenCode and GitHub Copilot.

1.6k
+75/day
+972 in 7d
Stars per day over 23 days, peak 418 3d ago
16321d agoPython
2
openqodex/openqodex

Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed, then a separate reviewer process that checks every scanner finding and is given every changed line. No other API key.

516
+74/day
+516 in 7d
Stars per day over 9 days, peak 242 3d ago
347d agoTypeScript
3
mdpsec/bug‑bounty‑hunting‑prompts

Reusable prompts for a structured, evidence-first bug bounty hunting workflow

521
+58/day
+383 in 7d
Stars per day over 8 days, peak 150 7d ago
1159d ago
4
Sequester-AG/bug‑bounty‑triage

Agent skill for rigorous bug bounty report triage, validation, severity escalation, and submission-ready reporting.

46
+46/day
81d ago
5
strands-agents/box

Run AI agents in a sandbox that restricts what they can execute, read, write, and reach on the network. Box combines OS isolation with default-deny Dogwood policies and credential injection that keeps secrets outside the agent. Written in Rust. Supports macOS on Apple silicon, with Linux support planned.

296
+42/day
+295 in 7d
Stars per day over 4 days, peak 159 2d ago
127d agoRust
6
nealbridges/VulnHunter

Agentic AI security scanner that hunts exploitable vulnerabilities like an adversary, proves them with executable PoCs, and fixes them test-first. A maintained fork of Capital One's VulnHunter, rebuilt for any agent harness.

678
+40/day
+680 in 7d
Stars per day over 6 days, peak 416 4d ago
10517d agoPython
7
aixisstudio/Snitch

Real-time network traffic visualizer — see every connection your computer makes. Privacy-first, 100% local. / Visualiseur de trafic réseau en temps réel, 100% local.

194
+24/day
+187 in 7d
Stars per day over 10 days, peak 96 1d ago
148d agoPython
8
nhovongoc0-max/meme‑radar

Meme雷达开源版:本地只读、多链 Meme 候选扫描与人工复核工具

527
+19/day
+39 in 7d
Stars per day over 30 days, peak 125 28d ago
19328d agoJavaScript
9
shinthink/blitzstrike

Blitz Strike — a universal MCP security-audit toolbelt. Reconnaissance at speed. Analysis in depth. Validation before report.

503
+19/day
+7 in 7d
Stars per day over 29 days, peak 1.0k 23d ago
627d agoTypeScript
10
Blackfrost-AI/Cyber‑Frost‑Harness

Native red, blue, and purple security-agent harness for CYBER-FROST

50
+13/day
+50 in 7d
Stars per day over 6 days, peak 26 4d ago
74d agoPython
11
devZero-Security/redStackPRO

A canvas for red team infrastructure and cyber ranges. Compose a topology, export runnable Terraform and Ansible, and deploy it yourself. Your cloud credentials never leave your machine.

141
+10/day
+8 in 7d
Stars per day over 13 days, peak 59 11d ago
1614d agoPython
12
socai-io/jev‑social

Open-source, local-first social media research agent for Instagram, TikTok, and LinkedIn. Jev routes read-only steps; socai CLI captures cited browser evidence.

158
+8/day
+16 in 7d
Stars per day over 23 days, peak 24 16d ago
3521d agoJavaScript
13
brandynfisher/ToolReplay

Audit AI agent tool-call transcripts: hash-chain sealing, deterministic replay, and scope overreach checks. Dependency-free Python CLI.

184
+7/day
2125d agoPython
14
velvet-semicolon/action‑dist‑verify

Rebuild the JavaScript GitHub Actions your workflows pin and check that their committed dist matches the source.

69
+6/day
1011d agoTypeScript
15
Kerlooo/FreeOSINTUI

Free alternative to https://osint-ui.com

56
+6/day
+10 in 7d
Stars per day over 12 days, peak 20 10d ago
610d agoJavaScript
16
CassiopeiaCode/CosyRedactGateway

Lightweight, stateless privacy gateway for LLM APIs — redact secrets before OpenAI/Anthropic upstreams and restore them transparently in SSE and tool calls.

100
+4/day
+2 in 7d
Stars per day over 30 days, peak 26 23d ago
2428d agoJavaScript
17
7wp81x/NRSuite‑Android

No-root Android + ESP32 Wi-Fi/BLE security testing toolkit. Deauth, captive portal, packet capture, BLE HID, and defense/detection modules, controlled over USB-OTG, no custom kernel or external adapter required.

102
+4/day
+39 in 7d
Stars per day over 25 days, peak 33 8d ago
1324d agoKotlin
18
DeathShotXD/Comment2Shell

Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post and drops a self deleting webshell. Full chain PoC with scanner interactive shell Nuclei template and Docker

63
+4/day
+2 in 7d
Stars per day over 16 days, peak 24 14d ago
1515d agoPython
19
leepokai/jev‑guard

Auto mode for every coding agent, built on Jev: risk-scores every tool call with session context (deny / ask / allow), flags prompt injection in results, checks skills and plugins. Claude Code, Codex, Copilot, Gemini, Cursor, pi, OpenCode, ACP.

63
+3/day
+7 in 7d
Stars per day over 24 days, peak 8 13d ago
1022d agoJavaScript
20
Mister-iks/pcybox‑attackgraph

Open source browser lab to build a simulated infrastructure, watch an attack move through it, and check whether your defense works.

46
+3/day
+2 in 7d
Stars per day over 15 days, peak 14 12d ago
814d agoTypeScript
21
g13net/lockjaw

Rust based C2 Framework

30
+3/day
+5 in 7d
Stars per day over 11 days, peak 14 9d ago
510d agoZig
22
cn0xroot/CC‑Monitor

Claude Code Monitor : Monitor & audit every action Claude Code takes on your computer.

65
+2/day
+3 in 7d
Stars per day over 29 days, peak 16 9d ago
927d agoJavaScript
23
Ethan-Andrews/ThreatIntel‑Aggregator

Self-hosted threat intelligence platform — feed aggregation, AI triage, MITRE ATT&CK coverage, and Sentinel-integrated detection engineering. Runs standalone or fully Azure-integrated.

59
+2/day
+3 in 7d
Stars per day over 27 days, peak 26 25d ago
725d agoPython
24
Justinuse1/pojia‑breaker

Chinese-first LLM jailbreak benchmark & red-team toolkit | 中文LLM安全评测框架 | by POJIA.AI

33
+2/day
+6 in 7d
Stars per day over 17 days, peak 8 15d ago
516d agoJavaScript
25
mdpsec/should‑i‑submit

A local, safety-first pre-submission reviewer for bug bounty reports.

37
+2/day
+5 in 7d
Stars per day over 22 days, peak 16 21d ago
621d ago
26
CodeByPinar/riskops

BT ve siber güvenlik risk yönetimi platformu — risk envanteri, 5×5 değerlendirme, aksiyon takibi ve kurumsal raporlama. PHP 8.3 + MariaDB, framework ve CDN kullanmadan.

32
+1/day
+1 in 7d
Stars per day over 30 days, peak 17 28d ago
1028d agoPHP
27
grepleaks/grepleaks

Grepleaks — your AI pentest environment. An AI pentest agent that lives in your terminal.

29
+1/day
+16 in 7d
Stars per day over 24 days, peak 11 1d ago
623d agoTypeScript
28
shaikarifali/bundlebleed

AI/LLM-assisted JS Recon and vulnerability triage for authorized bug bounty testing & pentesting — scope-gated, passive-by-default, human-verified

34
+1/day
+0 in 7d
Stars per day over 28 days, peak 12 26d ago
826d agoPython
29
laoshu666/hermes‑seagull

🦅 Seagull Profile - Unrestricted CTF/Red-team AI personality for Hermes Agent | 海鸥破甲人格

39
+1/day
+8 in 7d
Stars per day over 30 days, peak 4 18d ago
1428d agoPowerShell
30
security-attack/RingKiller

RingKiller — BYOD PoC for vulnerable driver DCRCVDrv.sys. Abuses IOCTL 0x2205C0 to kill arbitrary processes from ring 0 via ZwTerminateProcess. EDR/AV termination primitive. Lab only.

26
+1/day
+1 in 7d
Stars per day over 29 days, peak 9 25d ago
627d agoC