Task-based pick

Security and pentest

Tools for security: pentest, reverse engineering, threat analysis with an agent. For specialists who work on their own systems and with explicit authorization. Every entry has a high risk level and a direct note: use only where you have permission.

12 tools

Tools in this pick

A practical security skills base for agents: web, API, privilege escalation, Active Directory, mobile, binaries and crypto

SkillHigh riskNo VPN needed2.3KRepository stars

A CLI agent for authorized pentesting: from a natural-language brief it runs recon, finds and verifies vulnerabilities and prepares a report

CLIHigh riskNo VPN needed3.5KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars

A skills router for authorized reverse engineering, pentest, CTF and threat analysis: it picks a methodology for the task and checks available tools

SkillHigh riskNo VPN needed38.6KRepository stars

A bridge between an MCP client and a Kali Linux terminal so the agent can run nmap, sqlmap, hydra and other tools for authorized pentesting and CTF

MCP serverHigh riskNo VPN needed829Repository stars

A pack of about fifty Claude Code subagents for authorized pentesting: planning, recon, exploit research and chaining, post-exploitation, detection and reportin

PluginHigh riskNo VPN needed2.3KRepository stars

An offensive security MCP server: the agent runs 150+ pentest and recon tools and drives automated target assessments

MCP serverHigh riskNo VPN needed12.2KRepository stars

A set of skills for external OSINT recon: methodology, tactical arsenal and deep attack-surface analysis for authorized assessments

SkillHigh riskNo VPN needed2.7KRepository stars

MCP Security Hub

Offensive Security MCP Servers

A set of Dockerized MCP servers for offensive security tools: nmap, nuclei, sqlmap, radare2, ghidra and more, driven by an AI assistant

MCP serverHigh riskNo VPN needed796Repository stars

An MCP server and agent toolkit for reverse engineering: Ghidra, Frida, x64dbg and Rizin for binary analysis, CTF and malware research

MCP serverHigh riskNo VPN needed1.2KRepository stars

A cybersecurity skill library: forensics, incident response, pentesting, cloud and malware analysis mapped to MITRE ATT&CK and NIST

SkillHigh riskNo VPN needed33.5KRepository stars

A security scanner for agent skills: finds prompt injection, data exfiltration and malicious code before you install

CLIMedium riskNo VPN needed2.6KRepository stars

FAQ

Is this legal?

The tools are neutral. It is legal to use them only on your own systems or with the owner written permission. Otherwise it is a violation.

Good for beginners?

Partly. There are learning packs for CTF, but most target prepared specialists.

Collect these tools into a pack and share with one link.