Highlights
Stars
《深入理解 AI Infra:量化分析与系统设计》(李博杰 著)开源书稿:从硬件约束和模型架构出发,量化推导 LLM 推理与训练系统设计。含全书正文、PDF、配套计算工具与实验
Framework for evaluating and improving agents
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
DeepSeek Harness: Everything is a Plugin.
Open source, composable payments platform | PCI compliant | SaaS and Self-host options | Enables connectivity to multiple payment, payout, fraud, vault and tokenization providers | Uplifts authoriz…
DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM.
Orchestrate thousands of agents and harnesses as a graph programatically
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we confi…
agent runtime security - zero trust, zero setup, zero latency agent sandbox
Run Claude Code inside n8n workflows: automated code review, docs and bug fixes from visual pipelines. Published on npm.
Python tool for converting files and office documents to Markdown.
Pentest Copilot is an AI-powered browser based ethical hacking assistant tool designed to streamline pentesting workflows.
[Archived] Legacy Python Kimi CLI, no longer maintained. Please use Kimi Code CLI: https://github.com/MoonshotAI/kimi-code
An open-source multi-provider AI assisted CLI development tool. Use whatever LLM you want to code in your terminal.
Anonymous Github is a proxy server to support anonymous browsing of Github repositories for open-science code and data.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
A lightweight, powerful framework for multi-agent workflows
A restricted execution environment for Python to run untrusted code.
CVE-Bench: A Benchmark for AI Agents’ Ability to Exploit Real-World Web Application Vulnerabilities
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
A blazingly fast compiler for statically-typed Python, written in Rust and powered by LLVM. Write Python, get native performance. 🐍⚡
awesome list of browser exploitation tutorials
Zip Slip Vulnerability (Arbitrary file write through archive extraction)
🥇 Amazon Nova AI Challenge Winner - ASTRA emerged victorious as the top attacking team in Amazon's global AI safety competition, defeating elite defending teams from universities worldwide in live …
Buttercup finds and patches software vulnerabilities