Open-source adversarial testing engine, SDK, and CLI for AI agents. Runs locally or against the Humanbound Platform.
Top SECURITY GitHub Repositories & Tools (2026)
Discover the most starred and trending open source tools tagged with #security.
Documenting my security research journey: This repository contains detailed vulnerability write-ups, proof-of-concept (PoC) exploits, and the custom automation tools I use for reconnaissance and system assessment.
A collection of android security related resources
The ZAP by Checkmarx Core project
Cryptomator for Windows, macOS, and Linux: Secure client-side encryption for your cloud storage, ensuring privacy and control over your data.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
Comprehensive 2026 OSINT guide โ 450+ tools, AI intelligence, methodologies & ethics across 35 sections for investigation & threat intel.
Web-based Traffic and Cybersecurity Network Traffic Monitoring
๐ Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. ๐ Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAML Authentication. MFA/2FA with App Authenticators and Yubico. ๐ Authorization with JWT/PASETO tokens. ๐
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
awesome game security [Welcome to PR]
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
End-to-end encrypted notes, tasks, files, passwords, journal and bookmarks. Keyed by a 12-word BIP-39 phrase: no email, no password, no account to leak. The full client source for web, desktop and mobile is published, along with the encryption (XChaCha20-Poly1305, HKDF-SHA256, Ed25519) and the threat model, so the privacy claims are falsifiable.
Light LDAP implementation
An agent-native web security workspace. Find vulnerabilities through red-teaming. Formally verify properties of Rust codes in Lean 4.
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSeek Harness, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.
Secure Boot & Measured Boot for NixOS [maintainers=@blitz @raitobezarius @nikstur]
A secure low code deception runtime framework, leveraging AI for System Virtualization.
AI-powered open-source platform for Attack Surface Management (OASM)