Open-source LLM eval and red teaming: test prompts, compare models, catch jailbreaks and data leaks locally and in CI.
Results for “Vulners”
35 tools found
AI-powered security platform combining automated pentesting, code review and cloud vulnerability scanning to find and fix exploitable issues before attackers do.
Free secrets scanner from Gitleaks' original creator: finds leaked API keys and passwords in code with far fewer false positives.
An AI pentester that attacks your own app every time you ship new code, proves which bugs are actually exploitable, and writes the fix for you.
A hired hacker team on retainer, but mostly automated — instead of paying for one big annual penetration test and hoping nothing changed since, Astra's AI agents keep probing your app, APIs, and cloud setup continuously and hand real security experts the
An open-source platform that runs automated penetration tests using a team of 18 AI agents coordinating 80+ security tools — probing your web apps, cloud, and infrastructure for real, exploitable vulnerabilities the way a human pentest team would, but con
A free, open-source tool that sits in front of npm, pip, cargo, and 15 other package managers and blocks you — or your AI coding agent — from installing a package with a known security vulnerability, before it ever touches your project.
A free tool that automatically tries to hack into your own web application to find security holes before a real attacker does, then proves each vulnerability actually works instead of just guessing at it.
An AI agent that behaves like a real hacker against your own applications — chaining exploits together automatically, proving they work, and telling your team exactly what to fix, continuously instead of once a year.
A hacking-simulation tool that uses a team of AI agents — each specialized like a real penetration-testing crew member — to automatically probe a system for security weaknesses, from initial scanning all the way to proving an exploit works.
A security scanner that doesn't just flag possible bugs like most tools — it tries to actually exploit them first, so you only see the ones that are real.
An automated security guard for apps built with AI coding tools like Cursor or Claude Code — it finds real, exploitable bugs and opens a pull request that fixes them.
A free search engine for security researchers that scans the public web for exposed .env files, open .git folders, and other misconfigured files on any domain.
A security platform that scans your code, pipelines, and AI coding tools for vulnerabilities across your whole software supply chain, then tries to auto-fix what it finds.
Free open-source tool that scans a Tailscale network for security misconfigurations — overly open access rules, weak auth settings, risky device permissions — and tells you exactly what to fix.
Your laptop probably has hundreds of npm packages, PyPI libraries, VS Code extensions and MCP servers installed — Bumblebee is a free scanner from Perplexity that checks all of them at once against known supply-chain threats, without running or modifying
A security platform that protects laptops, servers, and cloud accounts from hackers and malware from one dashboard — instead of running separate antivirus, cloud security, and identity protection tools that don't talk to each other.
A cloud security platform that maps how your code, cloud infrastructure, and running applications connect to each other into one picture, so security teams can see the actual attack path a hacker would take instead of chasing disconnected alerts.
A security platform that tests and monitors company AI systems for attacks like prompt injection, flagging and blocking manipulation attempts before they cause damage.
A real-time API and AI security platform that uses low-overhead traffic monitoring to discover every API and AI asset a company runs — including AI agents and LLMs — flag exposed sensitive data, and run offensive security tests against them.