AI驱动的代码漏洞自动化审计,于业界公开的实现思路汇总、跟踪与分析_By Tr0e
☆36Jan 23, 2026Updated 7 months ago
Alternatives and similar repositories for Awesome-AI-Code-Audit
Users that are interested in Awesome-AI-Code-Audit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 一款根据pom.xml获取引用的第三方组件的版本号并识别组件漏洞的工具☆23May 17, 2023Updated 3 years ago
- 基于函数级污点分析的 Java 源代码漏洞审计工具JavaSinkTracer,通过 Model Context Protocol (MCP) 为 AI 助手提供安全分析能力。☆117Oct 7, 2025Updated 11 months ago
- vshell-firewall is a flexible, high-performance TCP proxy service designed to block fingerprinting and reconnaissance attempts targeting …☆19Updated this week
- 基于Python javalang库开发的一款轻量级Java源代码审计工具,by Tr0e☆75Oct 23, 2025Updated 10 months ago
- AuditLuma是一个AI+智能体代码审计系统,它利用多个AI代理和先进的技术,包括多代理合作协议(MCP)和Self-RAG(检索增强生成),为代码库提供全面的安全分析,目前已经支持ollama部署的本地大模型☆250Aug 1, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- 专注于代码审计skill,最小化轻量化skill,只负责安全边界。☆1,022Jun 16, 2026Updated 3 months ago
- SQLRecorder是一个能够 实时记录SQL语句的工具,方便代码审计时对SQL注入的实时关注。(A proxy to record all passing SQL statements.)☆34Apr 5, 2025Updated last year
- FindSomething本地移植版--HeartK☆96Jul 15, 2025Updated last year
- YuC0de(雨蔻)是一款无编译的SAST工具,基于静态分析、图分析、LLM来识别代码中的通用漏洞如:SQL注入、RCE、SSRF、不安全的反序列化、XSS...☆40Mar 25, 2026Updated 5 months ago
- 专注AI大模型代码审计工具, 一款专业的代码安全分析软件,旨在帮助开发者和安全工程师识别代码中的潜在安全漏洞。该工具支持多种编程语言,集成了先进的AI分析技术,能够进行静态代码分析和智能漏洞检测。☆82Dec 9, 2025Updated 9 months ago
- 主要是我对市面上常见android hook工具的理解☆15Dec 20, 2022Updated 3 years ago
- 基于 ReAct 框架的安全分析 Agent,在终端中完成代码审计、渗透测试、主机防护☆82Jul 12, 2026Updated 2 months ago
- WhiteURLScan 是一款功能强大且高效的网站 URL 扫描与信息采集工具,旨在帮助用户快速、安全地扫描和采集网站信息。它支持多线程并发扫描、递归爬取、自动拼接、敏感信息检测、外部 URL 收集等多种功能,广泛应用于安全测试、信息收集、资产梳理等领域。☆18Aug 14, 2025Updated last year
- 调用AI的代码审计平台 | Utilize the AI-based code audit platform☆67Jun 11, 2026Updated 3 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- 生异形吗?挖掘构建你自己的Java内存马!☆15May 22, 2025Updated last year
- Web console for the Rshell C2 framework — Vue 3 + TypeScript + Element Plus☆32Sep 11, 2026Updated last week
- LeekShell 是一款完全自研的轻量级C2框架,采用 Python + C++ 架构,舍弃部分冗余功能以换取更高的隐蔽性与可控性。☆32Sep 9, 2026Updated last week
- 👻inject_und3ad -- 蚁剑(AntSword)插件☆24Aug 8, 2019Updated 7 years ago
- 一个基于LLM的多Agent全流程漏洞挖掘项目,支持PHP、Java、Python、Go、Node.js等多种语言项目环境搭建、漏洞分析、漏洞验证、报告产出。支持多Agent并发高效率沟通完成漏洞挖掘任务。☆176Apr 25, 2026Updated 4 months ago
- NebulaFinger | 一款高效的WEB与服务指纹识别工具 | 可用于LLM-MCP调用☆15Jun 24, 2025Updated last year
- Enhanced Repeater Manager - Burp Suite 增强重放插件☆18Aug 13, 2026Updated last month
- Java代码审计手册,关注于漏洞挖掘而非利用【持续更新】☆204Nov 21, 2024Updated last year
- Log all keyboard and terminal input/output for any app 记录任意程序的键盘输入和终端输入输出☆23Jul 14, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆25Aug 12, 2020Updated 6 years ago
- 整理容器逃逸相关的漏洞和exploits.☆14Apr 17, 2024Updated 2 years ago
- burp越权测试插件☆20Sep 3, 2026Updated 2 weeks ago
- MemShellParty 命令行客户端 + MCP 服务器:生成 Java 内存马、盲探测、连马验证、执行命令、传输文件,专给 AI Agent和安全测试人员使用。☆31Aug 7, 2026Updated last month
- Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC☆17Dec 21, 2023Updated 2 years ago
- Fenrir 是一个基于 MCP 协议与 AST 技术的代码审计工具,旨在解决安全研究与自动化代码审计领域中,面对大规模、结构复杂甚至反编译代码时,传统代码搜索与分析手段效率低、准确性差的问题。☆179Oct 21, 2025Updated 10 months ago
- SecKnowledge - Web与AI安全测试知识技能☆409Jun 17, 2026Updated 3 months ago
- A command-line utility to exploit Android Zygote injection (CVE-2024-31317)☆62Dec 17, 2025Updated 9 months ago
- 互联网数字垃圾回收专用废纸篓☆66Jan 23, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- 个人漏洞收集项目,包括复现环境、POC、EXP等☆28Mar 14, 2025Updated last year
- Tai-e学习记录☆17Apr 15, 2024Updated 2 years ago
- GadgetExplorer is a .NET command-line tool for finding potential deserialization gadget chains in managed applications. It scans one or m…☆16May 22, 2026Updated 3 months ago
- Java代码审计学习笔记☆13Dec 20, 2024Updated last year
- 简洁高效的代码审计agent☆93Updated this week
- PoC Exploiting Permission Bypass in Android's Download Provider (CVE-2018-9468)☆22Jan 15, 2020Updated 6 years ago
- The required tools and materials to perform Samy Kamkar's RollJam attack☆15Oct 30, 2020Updated 5 years ago