EvanThomasLuke/Awesome-AI-Hacking-Agents

List of AI Hacking Agents

684

71 commits

updated Aug 29, 2026

See the code

README

Awesome-AI-Hacking-Agents

List of AI Hacking Agents - WORK IN PROGRESS PLEASE CONTRIBUTE!! I know I'm missing many companies and several open source. I'm going to add benchmark results for the few that have results.

THESE REPOS ARE FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING PURPOSES ONLY.

Please submit any I'm missing. You can just submit an issue with repo link and I will add to tables with details.

There are currently ~64 open source AI hacking agents listed. I need to re-sort and recategorize, some technically aren't agents.

Will be posting a comparative feature analysis soon (memory types, tools, etc).

Come chat about AI hacking agents in the AI Hacking Discord https://discord.gg/9AJnkNe6RE

Todo

  • add last commit and stars with csv so people can sort. Also add all benchmark scores.
  • Merge tencent repos

Devin Deepwiki / Google Code Wiki

Each of the open source tools contains deep wiki and code wiki links. You can use the Devin deepwiki MCP when your developing with your AI IDE/Agents to query open source repos to help you see what features others agents have.

The free, public DeepWiki MCP server (https://mcp.deepwiki.com/mcp), which exposes structured tools (like ask_question, read_wiki_structure, and read_wiki_contents) that agents can call directly.Integrate it into your workflow by adding the MCP endpoint to tools-compatible agents/IDEs (Cursor, Claude Code, Windsurf, Continue.dev, etc.) — usually just a one-line config addition with no auth needed for public repos. Once connected, instruct your agent to leverage DeepWiki MCP (often paired with GitHub CLI) for tasks like:

https://docs.devin.ai/work-with-devin/deepwiki-mcp

Open Source (WIP)

These are sorted by release date.

Each github repo also contains a link to Devin deep wiki and Google Code wiki which provides detailed documentation and a Gemini chat interface to ask questions about the repo. (I've requested all of the columns without a link and will update once google processes them).

I'm still updating this list with benchmark scores and more comments.

#NameURLSourceCreated / PublishedNotesCodeWiki (empty are pending)DeepWiki (empty are pending)
1AutoPentest-DRLhttps://github.com/crond-jaist/AutoPentest-DRLGitHub2021-03-30Deep RL for automated pentestinghttps://codewiki.google/github.com/crond-jaist/autopentest-drlhttps://deepwiki.com/crond-jaist/AutoPentest-DRL
2Reaper (Ghost Security)https://github.com/ghostsecurity/reaperGitHub2022-11-28https://codewiki.google/github.com/ghostsecurity/reaperhttps://deepwiki.com/ghostsecurity/reaper
3PentestGPThttps://github.com/GreyDGL/PentestGPTGitHub2023-02-27USENIX Security 2024https://codewiki.google/github.com/greydgl/pentestgpthttps://deepwiki.com/GreyDGL/PentestGPT
4hackingBuddyGPThttps://github.com/ipa-lab/hackingBuddyGPTGitHub2023-08-02https://codewiki.google/github.com/ipa-lab/hackingbuddygpthttps://deepwiki.com/ipa-lab/hackingBuddyGPT
5Nebulahttps://github.com/berylliumsec/nebulaGitHub2023-09-30https://codewiki.google/github.com/berylliumsec/nebulahttps://deepwiki.com/berylliumsec/nebula
6nyuctf_agents (D-CIPHER)https://github.com/NYU-LLM-CTF/nyuctf_agentsGitHub2024-03-13arXiv: 2502.10931 (Feb 15 2025)https://codewiki.google/github.com/nyu-llm-ctf/nyuctf_agentshttps://deepwiki.com/NYU-LLM-CTF/nyuctf_agents
7Pentest-Swarm-AIhttps://github.com/Armur-Ai/Pentest-Swarm-AIGitHub2024-03-26https://codewiki.google/github.com/armur-ai/pentest-swarm-aihttps://deepwiki.com/Armur-Ai/Pentest-Swarm-AI
8ReaperAIhttps://github.com/tac01337/ReaperAIGitHub2024-04-19arXiv: 2406.07561 (May 9 2024)https://codewiki.google/github.com/tac01337/reaperaihttps://deepwiki.com/tac01337/ReaperAI
9BreachSeek (arXiv only)https://arxiv.org/abs/2409.03789arXiv2024-08-31No associated repo listed
10vulnhuntrhttps://github.com/protectai/vulnhuntrGitHub2024-10-15https://codewiki.google/github.com/protectai/vulnhuntrhttps://deepwiki.com/protectai/vulnhuntr
11HackSynthhttps://github.com/aielte-research/HackSynthGitHub2024-11-27https://codewiki.google/github.com/aielte-research/hacksynthhttps://deepwiki.com/aielte-research/HackSynth
12PentAGIhttps://github.com/vxcontrol/pentagiGitHub2025-01-06https://codewiki.google/github.com/vxcontrol/pentagihttps://deepwiki.com/vxcontrol/pentagi
13VulnBothttps://github.com/KHenryAegis/VulnBotGitHub2025-01-20https://codewiki.google/github.com/khenryaegis/vulnbothttps://deepwiki.com/KHenryAegis/VulnBot
14BoxPwnrhttps://github.com/0ca/BoxPwnrGitHub2025-01-26https://codewiki.google/github.com/0ca/boxpwnrhttps://deepwiki.com/0ca/BoxPwnr
15Agentic Radarhttps://github.com/splx-ai/agentic-radarGitHub2025-02-12https://codewiki.google/github.com/splx-ai/agentic-radarhttps://deepwiki.com/splx-ai/agentic-radar
16D-CIPHER (paper)https://arxiv.org/abs/2502.10931, repo: https://github.com/NYU-LLM-CTF/nyuctf_agenttarXiv, github2025-02-15Repo: NYU-LLM-CTF/nyuctf_agentshttps://codewiki.google/github.com/nyu-llm-ctf/nyuctf_agentshttps://deepwiki.com/NYU-LLM-CTF/nyuctf_agents
17Claude Codehttps://github.com/anthropics/claude-codeGitHub2025-02-22Plugins README linkedhttps://codewiki.google/github.com/anthropics/claude-codehttps://deepwiki.com/anthropics/claude-code
18CAI (Cybersecurity AI)https://github.com/aliasrobotics/caiGitHub2025-03-31https://codewiki.google/github.com/aliasrobotics/caihttps://deepwiki.com/aliasrobotics/cai
19agent-scanhttps://github.com/snyk/agent-scanGitHub2025-04-07https://codewiki.google/github.com/snyk/agent-scanhttps://deepwiki.com/snyk/agent-scan
20pentestagenthttps://github.com/GH05TCREW/pentestagentGitHub2025-05-15https://codewiki.google/github.com/gh05tcrew/pentestagenthttps://deepwiki.com/GH05TCREW/pentestagent
21Cyber-AutoAgenthttps://github.com/westonbrown/Cyber-AutoAgent (archived), active https://github.com/double16/cyber-autoagent-ngGitHub2025-05-2685% score on xbow top open source scorehttps://codewiki.google/github.com/westonbrown/cyber-autoagenthttps://deepwiki.com/westonbrown/Cyber-AutoAgent
22Decepticonhttps://github.com/purpleailab/decepticonGitHub2025-06-06https://codewiki.google/github.com/purpleailab/decepticonhttps://deepwiki.com/purpleailab/decepticon
23rainkhttps://github.com/BishopFox/rainkGitHub2025-06-12LLM document ranking used for vulnerability identification workflows.https://codewiki.google/github.com/bishopfox/rainkhttps://deepwiki.com/BishopFox/raink
24ghostcrewhttps://github.com/shakenetwork/ghostcrewGitHub2025-06-13https://codewiki.google/github.com/shakenetwork/ghostcrewhttps://deepwiki.com/shakenetwork/ghostcrew
25ARTEMIShttps://github.com/Stanford-Trinity/ARTEMISGitHub2025-07-07https://codewiki.google/github.com/stanford-trinity/artemishttps://deepwiki.com/Stanford-Trinity/ARTEMIS
26metishttps://github.com/arm/metisGitHub2025-07-07https://codewiki.google/github.com/arm/metishttps://deepwiki.com/arm/metis
27hexstrike-aihttps://github.com/0x4m4/hexstrike-aiGitHub2025-07-10https://codewiki.google/github.com/0x4m4/hexstrike-aihttps://deepwiki.com/0x4m4/hexstrike-ai
28fraimhttps://github.com/fraim-dev/fraimGitHub2025-07-10Framework for security teams to build AI-powered workflows that orchestrate agents, tools, and security outputs.https://codewiki.google/github.com/fraim-dev/fraimhttps://deepwiki.com/fraim-dev/fraim
29RepoAudithttps://github.com/PurCL/RepoAuditGitHub2025-07-10Autonomous LLM agent for repo-level code auditing with memory and on-demand codebase exploration.https://codewiki.google/github.com/purcl/repoaudithttps://deepwiki.com/PurCL/RepoAudit
30Repeater Strikehttps://github.com/hackvertor/repeat-strikeGitHub2025-07-17AI-powered Burp extension for expanding manual Repeater findings such as IDORs across proxy history.https://codewiki.google/github.com/hackvertor/repeat-strikehttps://deepwiki.com/hackvertor/repeat-strike
31deadend-clihttps://github.com/xoxruns/deadend-cliGitHub2025-07-22https://codewiki.google/github.com/xoxruns/deadend-clihttps://deepwiki.com/xoxruns/deadend-cli
32Strixhttps://github.com/usestrix/strixGitHub2025-08-05https://codewiki.google/github.com/usestrix/strixhttps://deepwiki.com/usestrix/strix
33hackeraihttps://github.com/hackerai-tech/hackeraiGitHub2025-08-09https://codewiki.google/github.com/hackerai-tech/hackeraihttps://deepwiki.com/hackerai-tech/hackerai
34NeuroSploithttps://github.com/CyberSecurityUP/NeuroSploitGitHub2025-08-17https://codewiki.google/github.com/cybersecurityup/neurosploithttps://deepwiki.com/CyberSecurityUP/NeuroSploit
35BruteForceAIhttps://github.com/MorDavid/BruteForceaiGitHub2025-08-25LLM-powered brute-force tool combining AI reasoning with automated login attacks.https://codewiki.google/github.com/mordavid/bruteforceaihttps://deepwiki.com/MorDavid/BruteForceai
36MAPTAhttps://github.com/arthurgervais/maptaGitHub2025-08-28arXiv: 2508.20816 (Aug 28 2025)https://codewiki.google/github.com/arthurgervais/maptahttps://deepwiki.com/arthurgervais/mapta
37Beelzebubhttps://github.com/mariocandela/beelzebubGitHub2025-08Offensive AI security toolkit and honeypot framework for malicious AI-agent behavior.https://codewiki.google/github.com/mariocandela/beelzebubhttps://deepwiki.com/mariocandela/beelzebub
38Houndhttps://github.com/scabench-org/houndGitHub2025-08Open-source autonomous agents for code security auditing; builds and refines knowledge graphs for deep code reasoning.https://codewiki.google/github.com/scabench-org/houndhttps://deepwiki.com/scabench-org/hound
39agentic-soc-platformhttps://github.com/FunnyWolf/agentic-soc-platformGitHub2025-09-07https://codewiki.google/github.com/funnywolf/agentic-soc-platformhttps://deepwiki.com/FunnyWolf/agentic-soc-platform
40seclab-taskflow-agenthttps://github.com/GitHubSecurityLab/seclab-taskflow-agentGitHub2025-09-08GitHub Security Labhttps://codewiki.google/github.com/githubsecuritylab/seclab-taskflow-agenthttps://deepwiki.com/GitHubSecurityLab/seclab-taskflow-agent
41auto-exploitshttps://github.com/Valmarelox/auto-exploitsGitHub2025-09-11Repository associated with generated exploit automation examples.https://codewiki.google/github.com/valmarelox/auto-exploitshttps://deepwiki.com/Valmarelox/auto-exploits
42Shannonhttps://github.com/KeygraphHQ/shannonGitHub2025-09-27repo claims high XBOW benchmark performance but they did a white-box analysis on a blackbox benchmark which is not a correct way to compare.https://codewiki.google/github.com/keygraphhq/shannonhttps://deepwiki.com/KeygraphHQ/shannon
43apexhttps://github.com/pensarai/apexGitHub2025-10-10https://codewiki.google/github.com/pensarai/apexhttps://deepwiki.com/pensarai/apex
44deep-eyehttps://github.com/zakirkun/deep-eyeGitHub2025-10-15https://codewiki.google/github.com/zakirkun/deep-eyehttps://deepwiki.com/zakirkun/deep-eye
45Raptorhttps://github.com/gadievron/raptorGitHub2025-10-17https://codewiki.google/github.com/gadievron/raptorhttps://deepwiki.com/gadievron/raptor
46aracnehttps://github.com/stratosphereips/aracneGitHub2025-10Autonomous agent for offensive and defensive SSH operations.https://codewiki.google/github.com/stratosphereips/aracnehttps://deepwiki.com/stratosphereips/aracne
47CyberStrikeAIhttps://github.com/Ed1s0nZ/CyberStrikeAIGitHub2025-11-08https://codewiki.google/github.com/ed1s0nz/cyberstrikeaihttps://deepwiki.com/Ed1s0nZ/CyberStrikeAI
48medusahttps://github.com/Pantheon-Security/medusaGitHub2025-11-15https://codewiki.google/github.com/pantheon-security/medusahttps://deepwiki.com/Pantheon-Security/medusa
49crossbow-agenthttps://github.com/harishsg993010/crossbow-agentGitHub2025-11-18https://codewiki.google/github.com/harishsg993010/crossbow-agenthttps://deepwiki.com/harishsg993010/crossbow-agent
50Wazuh-MCP-Serverhttps://github.com/gensecaihq/Wazuh-MCP-ServerGitHub2025-11MCP server exposing SIEM/EDR telemetry so agents can run hunting and response playbooks.https://codewiki.google/github.com/gensecaihq/wazuh-mcp-serverhttps://deepwiki.com/gensecaihq/Wazuh-MCP-Server
51Infernohttps://github.com/Adem035/InfernoGitHub2025-12-02https://codewiki.google/github.com/adem035/infernohttps://deepwiki.com/Adem035/Inferno
52Sydhttps://github.com/Sydsec/sydGitHub2025-12-03https://codewiki.google/github.com/sydsec/sydhttps://deepwiki.com/Sydsec/syd
53ai-soc-agenthttps://github.com/M507/ai-soc-agentGitHub2025-12-05https://codewiki.google/github.com/m507/ai-soc-agenthttps://deepwiki.com/M507/ai-soc-agent
54AgenticRedhttps://github.com/yuanjiayiy/AgenticRedGitHub2025-12-11https://codewiki.google/github.com/yuanjiayiy/agenticredhttps://deepwiki.com/yuanjiayiy/AgenticRed
55EVAhttps://github.com/ARCANGEL0/EVAGitHub2025-12-15https://codewiki.google/github.com/arcangel0/evahttps://deepwiki.com/ARCANGEL0/EVA
56Vulnhallahttps://github.com/cyberark/VulnhallaGitHub2025-12-18LLM-assisted CodeQL triage for reducing false positives while vulnerability hunting.https://codewiki.google/github.com/cyberark/vulnhallahttps://deepwiki.com/cyberark/Vulnhalla
57guardian-clihttps://github.com/zakirkun/guardian-cliGitHub2025-12-22https://codewiki.google/github.com/zakirkun/guardian-clihttps://deepwiki.com/zakirkun/guardian-cli
58VulnLLM-Rhttps://github.com/ucsb-mlsec/VulnLLM-RGitHub2025-12Reasoning-focused LLM + agent pipeline for project-level vulnerability discovery and evaluation.https://codewiki.google/github.com/ucsb-mlsec/vulnllm-rhttps://deepwiki.com/ucsb-mlsec/VulnLLM-R
59ai-sasthttps://github.com/rivian/ai-sastGitHub2026-01-20https://codewiki.google/github.com/rivian/ai-sasthttps://deepwiki.com/rivian/ai-sast
60burp-ai-agenthttps://github.com/six2dez/burp-ai-agentGitHub2026-01-27Integrates with Burp Suitehttps://codewiki.google/github.com/six2dez/burp-ai-agenthttps://deepwiki.com/six2dez/burp-ai-agent
61praxishttps://github.com/originsec/praxisGitHub2026-01-27https://codewiki.google/github.com/originsec/praxishttps://deepwiki.com/originsec/praxis
62arXiv: 2602.02164https://arxiv.org/html/2602.02164v2arXiv~2026-02-01Feb 2026 paper (ID prefix 2602), no public code
63llmitmhttps://github.com/cybersharkvin/llmitmGithub2/4/26https://codewiki.google/github.com/cybersharkvin/llmitmhttps://deepwiki.com/cybersharkvin/llmitm
64redamonhttps://github.com/samugit83/redamongithub2/8/26https://codewiki.google/github.com/samugit83/redamonhttps://deepwiki.com/samugit83/redamon
65CyberStrikehttps://github.com/CyberStrikeus/CyberStrikeGitHub2026-02-14https://codewiki.google/github.com/cyberstrikeus/cyberstrikehttps://deepwiki.com/CyberStrikeus/CyberStrike
66grimoirehttps://github.com/JoranHonig/grimoireGitHub2026-02-16https://codewiki.google/github.com/joranhonig/grimoirehttps://deepwiki.com/JoranHonig/grimoire
67ironcurtainhttps://github.com/provos/ironcurtainGitHub2026-02-21https://codewiki.google/github.com/provos/ironcurtainhttps://deepwiki.com/provos/ironcurtain
68OpenAnthttps://github.com/knostic/OpenAntGitHub2026-02-26https://codewiki.google/github.com/knostic/openanthttps://deepwiki.com/knostic/OpenAnt
69aireconhttps://github.com/pikpikcu/aireconGitHub2026-03-05https://codewiki.google/github.com/pikpikcu/aireconhttps://deepwiki.com/pikpikcu/airecon
70agentflowhttps://github.com/berabuddies/agentflowGitHub2026-03-08https://codewiki.google/github.com/berabuddies/agentflowhttps://deepwiki.com/berabuddies/agentflow
71ai-web3-securityhttps://github.com/pashov/ai-web3-securityGitHub2026-03-12https://codewiki.google/github.com/pashov/ai-web3-securityhttps://deepwiki.com/pashov/ai-web3-security
72llmchainhunterhttps://github.com/atredispartners/llmchainhunterGitHub2026-03-16Claude Code design/runbook for Java deserialization gadget-chain hunting.https://codewiki.google/github.com/atredispartners/llmchainhunterhttps://deepwiki.com/atredispartners/llmchainhunter
73operant-mcphttps://github.com/operantlabs/operant-mcpGitHub2026-03-22MCP server with 51 security testing tools across 19 modules (SQLi, XSS, CMDi, SSRF, path traversal, PCAP forensics, recon, memory forensics, malware analysis). Install via npx operant-mcp.https://codewiki.google/github.com/operantlabs/operant-mcphttps://deepwiki.com/operantlabs/operant-mcp
74ctf-agenthttps://github.com/verialabs/ctf-agentGitHub2026-03-23https://codewiki.google/github.com/verialabs/ctf-agenthttps://deepwiki.com/verialabs/ctf-agent
75red-runhttps://github.com/blacklanternsecurity/red-runGitHub2026-03-30Security assessment toolkit for Claude Code.https://codewiki.google/github.com/blacklanternsecurity/red-runhttps://deepwiki.com/blacklanternsecurity/red-run
76xalgorixhttps://github.com/xalgord/xalgorixGitHub2026-03Open-source AI pentesting agent.https://codewiki.google/github.com/xalgord/xalgorixhttps://deepwiki.com/xalgord/xalgorix
77VulnVibeshttps://github.com/anshumanbh/vulnvibesGitHub2026-04-02AI agent that reasons across microservices to find real vulnerabilities.https://codewiki.google/github.com/anshumanbh/vulnvibeshttps://deepwiki.com/anshumanbh/vulnvibes
78DeepZerohttps://github.com/416rehman/DeepZeroGitHub2026-04-07https://codewiki.google/github.com/416rehman/deepzerohttps://deepwiki.com/416rehman/DeepZero
79nano-analyzerhttps://github.com/weareaisle/nano-analyzerGitHub2026-04-14https://codewiki.google/github.com/weareaisle/nano-analyzerhttps://deepwiki.com/weareaisle/nano-analyzer
80clearwinghttps://github.com/Lazarus-AI/clearwingGitHub2026-04-14https://codewiki.google/github.com/lazarus-ai/clearwinghttps://deepwiki.com/Lazarus-AI/clearwing
81redaihttps://github.com/kpolley/redaiGitHub2026-04-30Terminal workbench for AI-driven vulnerability discovery and live validation with scanner and validator agents.https://codewiki.google/github.com/kpolley/redaihttps://deepwiki.com/kpolley/redai
82deepsechttps://github.com/vercel-labs/deepsecGitHub2026-04Coding-agent vulnerability discovery harness.https://codewiki.google/github.com/vercel-labs/deepsechttps://deepwiki.com/vercel-labs/deepsec
83pentest-aihttps://github.com/0xSteph/pentest-aiGitHub2026-04Offensive-security MCP server with wrapped tools and specialist agents.https://codewiki.google/github.com/0xsteph/pentest-aihttps://deepwiki.com/0xSteph/pentest-ai
84vlnrhttps://github.com/nandrzej/vlnrGitHub2026-04AI security agent for Python supply-chain review, exploit generation, and Docker validation.https://codewiki.google/github.com/nandrzej/vlnrhttps://deepwiki.com/nandrzej/vlnr
85claude-mythoshttps://github.com/anshug/claude-mythosGitHub2026-04Claude-oriented vulnerability discovery framework with recon, chaining, exploit validation, and triage agents.https://codewiki.google/github.com/anshug/claude-mythoshttps://deepwiki.com/anshug/claude-mythos
86AIMaphttps://github.com/BishopFox/aimapGitHub2026-05-07Discovers, fingerprints, scores, and tests internet-exposed AI agent infrastructure.https://codewiki.google/github.com/bishopfox/aimaphttps://deepwiki.com/BishopFox/aimap
87RAMPARThttps://github.com/microsoft/RAMPARTGitHub2026-05-28Pytest-native framework for safety and security testing of agentic AI applications.https://codewiki.google/github.com/microsoft/ramparthttps://deepwiki.com/microsoft/RAMPART
88autopentest-aihttps://github.com/bhavsec/autopentest-aiGitHubhttps://codewiki.google/github.com/bhavsec/autopentest-aihttps://deepwiki.com/bhavsec/autopentest-ai

DARPA AIxCC

ResourceURL
AIxCC Open Source Archivearchive.aicyberchallenge.com
DARPA 2025 AIxCC results announcementdarpa.mil/news/2025/aixcc-results

Tencent Challenge (WIP)

These are from Tencent challenge in fall 2025.

I need to review and add these to main list https://zc.tencent.com/competition/competitionHackathon?code=cha004

#NameURLSourceCreated / PublishedNotesCodeWiki (empty are pending)DeepWiki (empty are pending)
1ctfSolverhttps://github.com/passer-W/ctfSolverGitHub2025-12-04https://codewiki.google/github.com/passer-w/ctfsolverhttps://deepwiki.com/passer-W/ctfSolver
2LuaN1aoAgenthttps://github.com/SanMuzZzZz/LuaN1aoAgentGitHub2025-12-04https://codewiki.google/github.com/sanmuzzzzz/luan1aoagenthttps://deepwiki.com/SanMuzZzZz/LuaN1aoAgent
3tinyctferhttps://github.com/chainreactors/tinyctferGitHub2025-12-04https://codewiki.google/github.com/chainreactors/tinyctferhttps://deepwiki.com/chainreactors/tinyctfer
4hackthon_demohttps://github.com/Ghr07h/hackthon_demoGitHub2025-12-02https://codewiki.google/github.com/ghr07h/hackthon_demohttps://deepwiki.com/Ghr07h/hackthon_demo
5Neuro-Sploithttps://github.com/Neuro-SploitGitHubOrg/user link, not a repo
6xbow-competitionhttps://github.com/m-sec-org/xbow-competitionGitHub2025-12-03https://codewiki.google/github.com/m-sec-org/xbow-competitionhttps://deepwiki.com/m-sec-org/xbow-competition
7Cruiser_publichttps://github.com/TJR181/Cruiser_publicGitHub2025-12-02https://codewiki.google/github.com/tjr181/cruiser_publichttps://deepwiki.com/TJR181/Cruiser_public
8CHYing-agenthttps://github.com/yhy0/CHYing-agentGitHub2025-11-10https://codewiki.google/github.com/yhy0/chying-agenthttps://deepwiki.com/yhy0/CHYing-agent
9SickHackSharkhttps://github.com/SickHackPark/SickHackSharkGitHub2025-12-04https://codewiki.google/github.com/sickhackpark/sickhacksharkhttps://deepwiki.com/SickHackPark/SickHackShark
10PenAgenthttps://github.com/lcz24/PenAgentGitHub2025-11-21https://codewiki.google/github.com/lcz24/penagenthttps://deepwiki.com/lcz24/PenAgent
11newmaptahttps://github.com/HUST-JYHLab/newmaptaGitHub2025-12-01https://codewiki.google/github.com/hust-jyhlab/newmaptahttps://deepwiki.com/HUST-JYHLab/newmapta
12sub-agent-autopthttps://github.com/yyy1mu/sub-agent-autoptGitHub2025-11-19https://codewiki.google/github.com/yyy1mu/sub-agent-autopthttps://deepwiki.com/yyy1mu/sub-agent-autopt
13H-Pentesthttps://github.com/hexian2001/H-PentestGitHub2025-11-22https://codewiki.google/github.com/hexian2001/h-pentesthttps://deepwiki.com/hexian2001/H-Pentest
14AgentNotehttps://github.com/C1JC/AgentNoteGitHub2025-11-07https://codewiki.google/github.com/c1jc/agentnotehttps://deepwiki.com/C1JC/AgentNote
15BUUCTF_Agenthttps://github.com/MuWinds/BUUCTF_AgentGitHub2025-09-30https://codewiki.google/github.com/muwinds/buuctf_agenthttps://deepwiki.com/MuWinds/BUUCTF_Agent

Enterprise/Closed Source (WIP)

Papers list (WIP)

PaperFocusHighlights
Teams of LLM Agents can Exploit Zero-Day VulnerabilitiesMulti-Agent HackingDemonstrates coordination between agents to find/exploit zero-day flaws.
LLM Agents can Autonomously Hack WebsitesWeb SecurityEarly work showing agents can autonomously navigate and exploit websites.
RedTeamLLM: an Agentic AI framework for offensive securityOffense FrameworkA dedicated framework for automating various stages of a cyberattack.
Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host NetworksNetwork AttacksFocuses on red-teaming complex, multi-host enterprise environments.
HackSynth: LLM Agent and Evaluation Framework for Autonomous Penetration TestingPen-Testing AgentUses a planner-summarizer architecture for structured security testing.
LLMs as Hackers: Autonomous Linux Privilege Escalation AttacksPrivilege EscalationEvaluates models on their ability to gain root access on Linux systems.
LLM Agents can Autonomously Exploit One-day VulnerabilitiesN-day ExploitationFocuses on using known vulnerability reports to generate exploits.
CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application VulnerabilitiesBenchmarkingProvides a large dataset of real vulnerabilities to test agent performance.

Other (WIP)

https://github.com/qriousec/colony_agent https://github.com/adshao/flounder https://github.com/vulhunt-re/vulhunt

https://github.com/theteatoast/local-vuln-research-pipeline

https://github.com/cynative/cynative

https://github.com/gigioneggiando/argo

https://github.com/capitalone/vulnhunter

https://github.com/openai/codex-security

https://github.com/openhackai/OpenHack

https://github.com/thatskriptkid/re-harness

https://github.com/ivRodriguezCA/MobHunt

https://github.com/Awarexone/Agentic-Bug-Hunter

https://github.com/larlarua/AutoCVE

ToolSafe https://github.com/MurrayTom/ToolSafe AgentFence

lists https://github.com/scadastrangelove/awesome-ai-security-tools

Contributors

EvanThomasLuke

68 commits

DeathsPirate

1 commits

esxr

1 commits

rohnyn

1 commits

EvanThomasLuke/Awesome-AI-Hacking-Agents

List of AI Hacking Agents

684

71 commits

updated Aug 29, 2026

See the code

README

Awesome-AI-Hacking-Agents

List of AI Hacking Agents - WORK IN PROGRESS PLEASE CONTRIBUTE!! I know I'm missing many companies and several open source. I'm going to add benchmark results for the few that have results.

THESE REPOS ARE FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING PURPOSES ONLY.

Please submit any I'm missing. You can just submit an issue with repo link and I will add to tables with details.

There are currently ~64 open source AI hacking agents listed. I need to re-sort and recategorize, some technically aren't agents.

Will be posting a comparative feature analysis soon (memory types, tools, etc).

Come chat about AI hacking agents in the AI Hacking Discord https://discord.gg/9AJnkNe6RE

Todo

  • add last commit and stars with csv so people can sort. Also add all benchmark scores.
  • Merge tencent repos

Devin Deepwiki / Google Code Wiki

Each of the open source tools contains deep wiki and code wiki links. You can use the Devin deepwiki MCP when your developing with your AI IDE/Agents to query open source repos to help you see what features others agents have.

The free, public DeepWiki MCP server (https://mcp.deepwiki.com/mcp), which exposes structured tools (like ask_question, read_wiki_structure, and read_wiki_contents) that agents can call directly.Integrate it into your workflow by adding the MCP endpoint to tools-compatible agents/IDEs (Cursor, Claude Code, Windsurf, Continue.dev, etc.) — usually just a one-line config addition with no auth needed for public repos. Once connected, instruct your agent to leverage DeepWiki MCP (often paired with GitHub CLI) for tasks like:

https://docs.devin.ai/work-with-devin/deepwiki-mcp

Open Source (WIP)

These are sorted by release date.

Each github repo also contains a link to Devin deep wiki and Google Code wiki which provides detailed documentation and a Gemini chat interface to ask questions about the repo. (I've requested all of the columns without a link and will update once google processes them).

I'm still updating this list with benchmark scores and more comments.

#NameURLSourceCreated / PublishedNotesCodeWiki (empty are pending)DeepWiki (empty are pending)
1AutoPentest-DRLhttps://github.com/crond-jaist/AutoPentest-DRLGitHub2021-03-30Deep RL for automated pentestinghttps://codewiki.google/github.com/crond-jaist/autopentest-drlhttps://deepwiki.com/crond-jaist/AutoPentest-DRL
2Reaper (Ghost Security)https://github.com/ghostsecurity/reaperGitHub2022-11-28https://codewiki.google/github.com/ghostsecurity/reaperhttps://deepwiki.com/ghostsecurity/reaper
3PentestGPThttps://github.com/GreyDGL/PentestGPTGitHub2023-02-27USENIX Security 2024https://codewiki.google/github.com/greydgl/pentestgpthttps://deepwiki.com/GreyDGL/PentestGPT
4hackingBuddyGPThttps://github.com/ipa-lab/hackingBuddyGPTGitHub2023-08-02https://codewiki.google/github.com/ipa-lab/hackingbuddygpthttps://deepwiki.com/ipa-lab/hackingBuddyGPT
5Nebulahttps://github.com/berylliumsec/nebulaGitHub2023-09-30https://codewiki.google/github.com/berylliumsec/nebulahttps://deepwiki.com/berylliumsec/nebula
6nyuctf_agents (D-CIPHER)https://github.com/NYU-LLM-CTF/nyuctf_agentsGitHub2024-03-13arXiv: 2502.10931 (Feb 15 2025)https://codewiki.google/github.com/nyu-llm-ctf/nyuctf_agentshttps://deepwiki.com/NYU-LLM-CTF/nyuctf_agents
7Pentest-Swarm-AIhttps://github.com/Armur-Ai/Pentest-Swarm-AIGitHub2024-03-26https://codewiki.google/github.com/armur-ai/pentest-swarm-aihttps://deepwiki.com/Armur-Ai/Pentest-Swarm-AI
8ReaperAIhttps://github.com/tac01337/ReaperAIGitHub2024-04-19arXiv: 2406.07561 (May 9 2024)https://codewiki.google/github.com/tac01337/reaperaihttps://deepwiki.com/tac01337/ReaperAI
9BreachSeek (arXiv only)https://arxiv.org/abs/2409.03789arXiv2024-08-31No associated repo listed
10vulnhuntrhttps://github.com/protectai/vulnhuntrGitHub2024-10-15https://codewiki.google/github.com/protectai/vulnhuntrhttps://deepwiki.com/protectai/vulnhuntr
11HackSynthhttps://github.com/aielte-research/HackSynthGitHub2024-11-27https://codewiki.google/github.com/aielte-research/hacksynthhttps://deepwiki.com/aielte-research/HackSynth
12PentAGIhttps://github.com/vxcontrol/pentagiGitHub2025-01-06https://codewiki.google/github.com/vxcontrol/pentagihttps://deepwiki.com/vxcontrol/pentagi
13VulnBothttps://github.com/KHenryAegis/VulnBotGitHub2025-01-20https://codewiki.google/github.com/khenryaegis/vulnbothttps://deepwiki.com/KHenryAegis/VulnBot
14BoxPwnrhttps://github.com/0ca/BoxPwnrGitHub2025-01-26https://codewiki.google/github.com/0ca/boxpwnrhttps://deepwiki.com/0ca/BoxPwnr
15Agentic Radarhttps://github.com/splx-ai/agentic-radarGitHub2025-02-12https://codewiki.google/github.com/splx-ai/agentic-radarhttps://deepwiki.com/splx-ai/agentic-radar
16D-CIPHER (paper)https://arxiv.org/abs/2502.10931, repo: https://github.com/NYU-LLM-CTF/nyuctf_agenttarXiv, github2025-02-15Repo: NYU-LLM-CTF/nyuctf_agentshttps://codewiki.google/github.com/nyu-llm-ctf/nyuctf_agentshttps://deepwiki.com/NYU-LLM-CTF/nyuctf_agents
17Claude Codehttps://github.com/anthropics/claude-codeGitHub2025-02-22Plugins README linkedhttps://codewiki.google/github.com/anthropics/claude-codehttps://deepwiki.com/anthropics/claude-code
18CAI (Cybersecurity AI)https://github.com/aliasrobotics/caiGitHub2025-03-31https://codewiki.google/github.com/aliasrobotics/caihttps://deepwiki.com/aliasrobotics/cai
19agent-scanhttps://github.com/snyk/agent-scanGitHub2025-04-07https://codewiki.google/github.com/snyk/agent-scanhttps://deepwiki.com/snyk/agent-scan
20pentestagenthttps://github.com/GH05TCREW/pentestagentGitHub2025-05-15https://codewiki.google/github.com/gh05tcrew/pentestagenthttps://deepwiki.com/GH05TCREW/pentestagent
21Cyber-AutoAgenthttps://github.com/westonbrown/Cyber-AutoAgent (archived), active https://github.com/double16/cyber-autoagent-ngGitHub2025-05-2685% score on xbow top open source scorehttps://codewiki.google/github.com/westonbrown/cyber-autoagenthttps://deepwiki.com/westonbrown/Cyber-AutoAgent
22Decepticonhttps://github.com/purpleailab/decepticonGitHub2025-06-06https://codewiki.google/github.com/purpleailab/decepticonhttps://deepwiki.com/purpleailab/decepticon
23rainkhttps://github.com/BishopFox/rainkGitHub2025-06-12LLM document ranking used for vulnerability identification workflows.https://codewiki.google/github.com/bishopfox/rainkhttps://deepwiki.com/BishopFox/raink
24ghostcrewhttps://github.com/shakenetwork/ghostcrewGitHub2025-06-13https://codewiki.google/github.com/shakenetwork/ghostcrewhttps://deepwiki.com/shakenetwork/ghostcrew
25ARTEMIShttps://github.com/Stanford-Trinity/ARTEMISGitHub2025-07-07https://codewiki.google/github.com/stanford-trinity/artemishttps://deepwiki.com/Stanford-Trinity/ARTEMIS
26metishttps://github.com/arm/metisGitHub2025-07-07https://codewiki.google/github.com/arm/metishttps://deepwiki.com/arm/metis
27hexstrike-aihttps://github.com/0x4m4/hexstrike-aiGitHub2025-07-10https://codewiki.google/github.com/0x4m4/hexstrike-aihttps://deepwiki.com/0x4m4/hexstrike-ai
28fraimhttps://github.com/fraim-dev/fraimGitHub2025-07-10Framework for security teams to build AI-powered workflows that orchestrate agents, tools, and security outputs.https://codewiki.google/github.com/fraim-dev/fraimhttps://deepwiki.com/fraim-dev/fraim
29RepoAudithttps://github.com/PurCL/RepoAuditGitHub2025-07-10Autonomous LLM agent for repo-level code auditing with memory and on-demand codebase exploration.https://codewiki.google/github.com/purcl/repoaudithttps://deepwiki.com/PurCL/RepoAudit
30Repeater Strikehttps://github.com/hackvertor/repeat-strikeGitHub2025-07-17AI-powered Burp extension for expanding manual Repeater findings such as IDORs across proxy history.https://codewiki.google/github.com/hackvertor/repeat-strikehttps://deepwiki.com/hackvertor/repeat-strike
31deadend-clihttps://github.com/xoxruns/deadend-cliGitHub2025-07-22https://codewiki.google/github.com/xoxruns/deadend-clihttps://deepwiki.com/xoxruns/deadend-cli
32Strixhttps://github.com/usestrix/strixGitHub2025-08-05https://codewiki.google/github.com/usestrix/strixhttps://deepwiki.com/usestrix/strix
33hackeraihttps://github.com/hackerai-tech/hackeraiGitHub2025-08-09https://codewiki.google/github.com/hackerai-tech/hackeraihttps://deepwiki.com/hackerai-tech/hackerai
34NeuroSploithttps://github.com/CyberSecurityUP/NeuroSploitGitHub2025-08-17https://codewiki.google/github.com/cybersecurityup/neurosploithttps://deepwiki.com/CyberSecurityUP/NeuroSploit
35BruteForceAIhttps://github.com/MorDavid/BruteForceaiGitHub2025-08-25LLM-powered brute-force tool combining AI reasoning with automated login attacks.https://codewiki.google/github.com/mordavid/bruteforceaihttps://deepwiki.com/MorDavid/BruteForceai
36MAPTAhttps://github.com/arthurgervais/maptaGitHub2025-08-28arXiv: 2508.20816 (Aug 28 2025)https://codewiki.google/github.com/arthurgervais/maptahttps://deepwiki.com/arthurgervais/mapta
37Beelzebubhttps://github.com/mariocandela/beelzebubGitHub2025-08Offensive AI security toolkit and honeypot framework for malicious AI-agent behavior.https://codewiki.google/github.com/mariocandela/beelzebubhttps://deepwiki.com/mariocandela/beelzebub
38Houndhttps://github.com/scabench-org/houndGitHub2025-08Open-source autonomous agents for code security auditing; builds and refines knowledge graphs for deep code reasoning.https://codewiki.google/github.com/scabench-org/houndhttps://deepwiki.com/scabench-org/hound
39agentic-soc-platformhttps://github.com/FunnyWolf/agentic-soc-platformGitHub2025-09-07https://codewiki.google/github.com/funnywolf/agentic-soc-platformhttps://deepwiki.com/FunnyWolf/agentic-soc-platform
40seclab-taskflow-agenthttps://github.com/GitHubSecurityLab/seclab-taskflow-agentGitHub2025-09-08GitHub Security Labhttps://codewiki.google/github.com/githubsecuritylab/seclab-taskflow-agenthttps://deepwiki.com/GitHubSecurityLab/seclab-taskflow-agent
41auto-exploitshttps://github.com/Valmarelox/auto-exploitsGitHub2025-09-11Repository associated with generated exploit automation examples.https://codewiki.google/github.com/valmarelox/auto-exploitshttps://deepwiki.com/Valmarelox/auto-exploits
42Shannonhttps://github.com/KeygraphHQ/shannonGitHub2025-09-27repo claims high XBOW benchmark performance but they did a white-box analysis on a blackbox benchmark which is not a correct way to compare.https://codewiki.google/github.com/keygraphhq/shannonhttps://deepwiki.com/KeygraphHQ/shannon
43apexhttps://github.com/pensarai/apexGitHub2025-10-10https://codewiki.google/github.com/pensarai/apexhttps://deepwiki.com/pensarai/apex
44deep-eyehttps://github.com/zakirkun/deep-eyeGitHub2025-10-15https://codewiki.google/github.com/zakirkun/deep-eyehttps://deepwiki.com/zakirkun/deep-eye
45Raptorhttps://github.com/gadievron/raptorGitHub2025-10-17https://codewiki.google/github.com/gadievron/raptorhttps://deepwiki.com/gadievron/raptor
46aracnehttps://github.com/stratosphereips/aracneGitHub2025-10Autonomous agent for offensive and defensive SSH operations.https://codewiki.google/github.com/stratosphereips/aracnehttps://deepwiki.com/stratosphereips/aracne
47CyberStrikeAIhttps://github.com/Ed1s0nZ/CyberStrikeAIGitHub2025-11-08https://codewiki.google/github.com/ed1s0nz/cyberstrikeaihttps://deepwiki.com/Ed1s0nZ/CyberStrikeAI
48medusahttps://github.com/Pantheon-Security/medusaGitHub2025-11-15https://codewiki.google/github.com/pantheon-security/medusahttps://deepwiki.com/Pantheon-Security/medusa
49crossbow-agenthttps://github.com/harishsg993010/crossbow-agentGitHub2025-11-18https://codewiki.google/github.com/harishsg993010/crossbow-agenthttps://deepwiki.com/harishsg993010/crossbow-agent
50Wazuh-MCP-Serverhttps://github.com/gensecaihq/Wazuh-MCP-ServerGitHub2025-11MCP server exposing SIEM/EDR telemetry so agents can run hunting and response playbooks.https://codewiki.google/github.com/gensecaihq/wazuh-mcp-serverhttps://deepwiki.com/gensecaihq/Wazuh-MCP-Server
51Infernohttps://github.com/Adem035/InfernoGitHub2025-12-02https://codewiki.google/github.com/adem035/infernohttps://deepwiki.com/Adem035/Inferno
52Sydhttps://github.com/Sydsec/sydGitHub2025-12-03https://codewiki.google/github.com/sydsec/sydhttps://deepwiki.com/Sydsec/syd
53ai-soc-agenthttps://github.com/M507/ai-soc-agentGitHub2025-12-05https://codewiki.google/github.com/m507/ai-soc-agenthttps://deepwiki.com/M507/ai-soc-agent
54AgenticRedhttps://github.com/yuanjiayiy/AgenticRedGitHub2025-12-11https://codewiki.google/github.com/yuanjiayiy/agenticredhttps://deepwiki.com/yuanjiayiy/AgenticRed
55EVAhttps://github.com/ARCANGEL0/EVAGitHub2025-12-15https://codewiki.google/github.com/arcangel0/evahttps://deepwiki.com/ARCANGEL0/EVA
56Vulnhallahttps://github.com/cyberark/VulnhallaGitHub2025-12-18LLM-assisted CodeQL triage for reducing false positives while vulnerability hunting.https://codewiki.google/github.com/cyberark/vulnhallahttps://deepwiki.com/cyberark/Vulnhalla
57guardian-clihttps://github.com/zakirkun/guardian-cliGitHub2025-12-22https://codewiki.google/github.com/zakirkun/guardian-clihttps://deepwiki.com/zakirkun/guardian-cli
58VulnLLM-Rhttps://github.com/ucsb-mlsec/VulnLLM-RGitHub2025-12Reasoning-focused LLM + agent pipeline for project-level vulnerability discovery and evaluation.https://codewiki.google/github.com/ucsb-mlsec/vulnllm-rhttps://deepwiki.com/ucsb-mlsec/VulnLLM-R
59ai-sasthttps://github.com/rivian/ai-sastGitHub2026-01-20https://codewiki.google/github.com/rivian/ai-sasthttps://deepwiki.com/rivian/ai-sast
60burp-ai-agenthttps://github.com/six2dez/burp-ai-agentGitHub2026-01-27Integrates with Burp Suitehttps://codewiki.google/github.com/six2dez/burp-ai-agenthttps://deepwiki.com/six2dez/burp-ai-agent
61praxishttps://github.com/originsec/praxisGitHub2026-01-27https://codewiki.google/github.com/originsec/praxishttps://deepwiki.com/originsec/praxis
62arXiv: 2602.02164https://arxiv.org/html/2602.02164v2arXiv~2026-02-01Feb 2026 paper (ID prefix 2602), no public code
63llmitmhttps://github.com/cybersharkvin/llmitmGithub2/4/26https://codewiki.google/github.com/cybersharkvin/llmitmhttps://deepwiki.com/cybersharkvin/llmitm
64redamonhttps://github.com/samugit83/redamongithub2/8/26https://codewiki.google/github.com/samugit83/redamonhttps://deepwiki.com/samugit83/redamon
65CyberStrikehttps://github.com/CyberStrikeus/CyberStrikeGitHub2026-02-14https://codewiki.google/github.com/cyberstrikeus/cyberstrikehttps://deepwiki.com/CyberStrikeus/CyberStrike
66grimoirehttps://github.com/JoranHonig/grimoireGitHub2026-02-16https://codewiki.google/github.com/joranhonig/grimoirehttps://deepwiki.com/JoranHonig/grimoire
67ironcurtainhttps://github.com/provos/ironcurtainGitHub2026-02-21https://codewiki.google/github.com/provos/ironcurtainhttps://deepwiki.com/provos/ironcurtain
68OpenAnthttps://github.com/knostic/OpenAntGitHub2026-02-26https://codewiki.google/github.com/knostic/openanthttps://deepwiki.com/knostic/OpenAnt
69aireconhttps://github.com/pikpikcu/aireconGitHub2026-03-05https://codewiki.google/github.com/pikpikcu/aireconhttps://deepwiki.com/pikpikcu/airecon
70agentflowhttps://github.com/berabuddies/agentflowGitHub2026-03-08https://codewiki.google/github.com/berabuddies/agentflowhttps://deepwiki.com/berabuddies/agentflow
71ai-web3-securityhttps://github.com/pashov/ai-web3-securityGitHub2026-03-12https://codewiki.google/github.com/pashov/ai-web3-securityhttps://deepwiki.com/pashov/ai-web3-security
72llmchainhunterhttps://github.com/atredispartners/llmchainhunterGitHub2026-03-16Claude Code design/runbook for Java deserialization gadget-chain hunting.https://codewiki.google/github.com/atredispartners/llmchainhunterhttps://deepwiki.com/atredispartners/llmchainhunter
73operant-mcphttps://github.com/operantlabs/operant-mcpGitHub2026-03-22MCP server with 51 security testing tools across 19 modules (SQLi, XSS, CMDi, SSRF, path traversal, PCAP forensics, recon, memory forensics, malware analysis). Install via npx operant-mcp.https://codewiki.google/github.com/operantlabs/operant-mcphttps://deepwiki.com/operantlabs/operant-mcp
74ctf-agenthttps://github.com/verialabs/ctf-agentGitHub2026-03-23https://codewiki.google/github.com/verialabs/ctf-agenthttps://deepwiki.com/verialabs/ctf-agent
75red-runhttps://github.com/blacklanternsecurity/red-runGitHub2026-03-30Security assessment toolkit for Claude Code.https://codewiki.google/github.com/blacklanternsecurity/red-runhttps://deepwiki.com/blacklanternsecurity/red-run
76xalgorixhttps://github.com/xalgord/xalgorixGitHub2026-03Open-source AI pentesting agent.https://codewiki.google/github.com/xalgord/xalgorixhttps://deepwiki.com/xalgord/xalgorix
77VulnVibeshttps://github.com/anshumanbh/vulnvibesGitHub2026-04-02AI agent that reasons across microservices to find real vulnerabilities.https://codewiki.google/github.com/anshumanbh/vulnvibeshttps://deepwiki.com/anshumanbh/vulnvibes
78DeepZerohttps://github.com/416rehman/DeepZeroGitHub2026-04-07https://codewiki.google/github.com/416rehman/deepzerohttps://deepwiki.com/416rehman/DeepZero
79nano-analyzerhttps://github.com/weareaisle/nano-analyzerGitHub2026-04-14https://codewiki.google/github.com/weareaisle/nano-analyzerhttps://deepwiki.com/weareaisle/nano-analyzer
80clearwinghttps://github.com/Lazarus-AI/clearwingGitHub2026-04-14https://codewiki.google/github.com/lazarus-ai/clearwinghttps://deepwiki.com/Lazarus-AI/clearwing
81redaihttps://github.com/kpolley/redaiGitHub2026-04-30Terminal workbench for AI-driven vulnerability discovery and live validation with scanner and validator agents.https://codewiki.google/github.com/kpolley/redaihttps://deepwiki.com/kpolley/redai
82deepsechttps://github.com/vercel-labs/deepsecGitHub2026-04Coding-agent vulnerability discovery harness.https://codewiki.google/github.com/vercel-labs/deepsechttps://deepwiki.com/vercel-labs/deepsec
83pentest-aihttps://github.com/0xSteph/pentest-aiGitHub2026-04Offensive-security MCP server with wrapped tools and specialist agents.https://codewiki.google/github.com/0xsteph/pentest-aihttps://deepwiki.com/0xSteph/pentest-ai
84vlnrhttps://github.com/nandrzej/vlnrGitHub2026-04AI security agent for Python supply-chain review, exploit generation, and Docker validation.https://codewiki.google/github.com/nandrzej/vlnrhttps://deepwiki.com/nandrzej/vlnr
85claude-mythoshttps://github.com/anshug/claude-mythosGitHub2026-04Claude-oriented vulnerability discovery framework with recon, chaining, exploit validation, and triage agents.https://codewiki.google/github.com/anshug/claude-mythoshttps://deepwiki.com/anshug/claude-mythos
86AIMaphttps://github.com/BishopFox/aimapGitHub2026-05-07Discovers, fingerprints, scores, and tests internet-exposed AI agent infrastructure.https://codewiki.google/github.com/bishopfox/aimaphttps://deepwiki.com/BishopFox/aimap
87RAMPARThttps://github.com/microsoft/RAMPARTGitHub2026-05-28Pytest-native framework for safety and security testing of agentic AI applications.https://codewiki.google/github.com/microsoft/ramparthttps://deepwiki.com/microsoft/RAMPART
88autopentest-aihttps://github.com/bhavsec/autopentest-aiGitHubhttps://codewiki.google/github.com/bhavsec/autopentest-aihttps://deepwiki.com/bhavsec/autopentest-ai

DARPA AIxCC

ResourceURL
AIxCC Open Source Archivearchive.aicyberchallenge.com
DARPA 2025 AIxCC results announcementdarpa.mil/news/2025/aixcc-results

Tencent Challenge (WIP)

These are from Tencent challenge in fall 2025.

I need to review and add these to main list https://zc.tencent.com/competition/competitionHackathon?code=cha004

#NameURLSourceCreated / PublishedNotesCodeWiki (empty are pending)DeepWiki (empty are pending)
1ctfSolverhttps://github.com/passer-W/ctfSolverGitHub2025-12-04https://codewiki.google/github.com/passer-w/ctfsolverhttps://deepwiki.com/passer-W/ctfSolver
2LuaN1aoAgenthttps://github.com/SanMuzZzZz/LuaN1aoAgentGitHub2025-12-04https://codewiki.google/github.com/sanmuzzzzz/luan1aoagenthttps://deepwiki.com/SanMuzZzZz/LuaN1aoAgent
3tinyctferhttps://github.com/chainreactors/tinyctferGitHub2025-12-04https://codewiki.google/github.com/chainreactors/tinyctferhttps://deepwiki.com/chainreactors/tinyctfer
4hackthon_demohttps://github.com/Ghr07h/hackthon_demoGitHub2025-12-02https://codewiki.google/github.com/ghr07h/hackthon_demohttps://deepwiki.com/Ghr07h/hackthon_demo
5Neuro-Sploithttps://github.com/Neuro-SploitGitHubOrg/user link, not a repo
6xbow-competitionhttps://github.com/m-sec-org/xbow-competitionGitHub2025-12-03https://codewiki.google/github.com/m-sec-org/xbow-competitionhttps://deepwiki.com/m-sec-org/xbow-competition
7Cruiser_publichttps://github.com/TJR181/Cruiser_publicGitHub2025-12-02https://codewiki.google/github.com/tjr181/cruiser_publichttps://deepwiki.com/TJR181/Cruiser_public
8CHYing-agenthttps://github.com/yhy0/CHYing-agentGitHub2025-11-10https://codewiki.google/github.com/yhy0/chying-agenthttps://deepwiki.com/yhy0/CHYing-agent
9SickHackSharkhttps://github.com/SickHackPark/SickHackSharkGitHub2025-12-04https://codewiki.google/github.com/sickhackpark/sickhacksharkhttps://deepwiki.com/SickHackPark/SickHackShark
10PenAgenthttps://github.com/lcz24/PenAgentGitHub2025-11-21https://codewiki.google/github.com/lcz24/penagenthttps://deepwiki.com/lcz24/PenAgent
11newmaptahttps://github.com/HUST-JYHLab/newmaptaGitHub2025-12-01https://codewiki.google/github.com/hust-jyhlab/newmaptahttps://deepwiki.com/HUST-JYHLab/newmapta
12sub-agent-autopthttps://github.com/yyy1mu/sub-agent-autoptGitHub2025-11-19https://codewiki.google/github.com/yyy1mu/sub-agent-autopthttps://deepwiki.com/yyy1mu/sub-agent-autopt
13H-Pentesthttps://github.com/hexian2001/H-PentestGitHub2025-11-22https://codewiki.google/github.com/hexian2001/h-pentesthttps://deepwiki.com/hexian2001/H-Pentest
14AgentNotehttps://github.com/C1JC/AgentNoteGitHub2025-11-07https://codewiki.google/github.com/c1jc/agentnotehttps://deepwiki.com/C1JC/AgentNote
15BUUCTF_Agenthttps://github.com/MuWinds/BUUCTF_AgentGitHub2025-09-30https://codewiki.google/github.com/muwinds/buuctf_agenthttps://deepwiki.com/MuWinds/BUUCTF_Agent

Enterprise/Closed Source (WIP)

Papers list (WIP)

PaperFocusHighlights
Teams of LLM Agents can Exploit Zero-Day VulnerabilitiesMulti-Agent HackingDemonstrates coordination between agents to find/exploit zero-day flaws.
LLM Agents can Autonomously Hack WebsitesWeb SecurityEarly work showing agents can autonomously navigate and exploit websites.
RedTeamLLM: an Agentic AI framework for offensive securityOffense FrameworkA dedicated framework for automating various stages of a cyberattack.
Incalmo: An Autonomous LLM-assisted System for Red Teaming Multi-Host NetworksNetwork AttacksFocuses on red-teaming complex, multi-host enterprise environments.
HackSynth: LLM Agent and Evaluation Framework for Autonomous Penetration TestingPen-Testing AgentUses a planner-summarizer architecture for structured security testing.
LLMs as Hackers: Autonomous Linux Privilege Escalation AttacksPrivilege EscalationEvaluates models on their ability to gain root access on Linux systems.
LLM Agents can Autonomously Exploit One-day VulnerabilitiesN-day ExploitationFocuses on using known vulnerability reports to generate exploits.
CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application VulnerabilitiesBenchmarkingProvides a large dataset of real vulnerabilities to test agent performance.

Other (WIP)

https://github.com/qriousec/colony_agent https://github.com/adshao/flounder https://github.com/vulhunt-re/vulhunt

https://github.com/theteatoast/local-vuln-research-pipeline

https://github.com/cynative/cynative

https://github.com/gigioneggiando/argo

https://github.com/capitalone/vulnhunter

https://github.com/openai/codex-security

https://github.com/openhackai/OpenHack

https://github.com/thatskriptkid/re-harness

https://github.com/ivRodriguezCA/MobHunt

https://github.com/Awarexone/Agentic-Bug-Hunter

https://github.com/larlarua/AutoCVE

ToolSafe https://github.com/MurrayTom/ToolSafe AgentFence

lists https://github.com/scadastrangelove/awesome-ai-security-tools

Contributors

EvanThomasLuke

68 commits

DeathsPirate

1 commits

esxr

1 commits

rohnyn

1 commits