4,053 tools found
Recovers how a web app signs or encrypts API requests via an Observe-Capture-Rebuild-Patch-DeepDive JS reverse-engineering workflow.
Delegate bounded coding tasks to the Kimi Code CLI, which has no read-only mode at all, then verify every run against the actual diff.
Red-teams LLM apps and AI agents for prompt injection, tool abuse, memory poisoning, and prompt leakage, mapped to OWASP LLM/ASI Top 10.
Reverse-engineers macOS Mach-O binaries and app bundles: signatures, entitlements, ObjC/Swift structures, and TCC-sensitive APIs.
A six-phase malware triage-to-detection workflow: static/dynamic analysis in an isolated sandbox, then YARA, Sigma, and IOC output.
Reverse-engineers Android APK and iOS IPA apps: static analysis, Frida/Objection instrumentation, and SSL pinning or root-detection bypass.
A submit-and-poll skill for MuAPI's async image/video generation API: one model catalog, no per-provider integration.
Delegate bounded coding tasks to Oh My Pi (omp), an unsandboxed fork of Pi that always runs --yolo headlessly, then review the diff before landing it.
Delegate a bounded coding task to the OpenCode CLI, naming a model explicitly, then review the diff before you commit.
Passively assesses OT/ICS networks against the Purdue model, documenting PLC/SCADA/HMI exposure and Modbus/DNP3/S7 protocol weaknesses.
Turns a vendor patch into a located vulnerability by binary-diffing before/after builds, for authorized N-day research.
Orchestrates standard pentest tooling (Nmap, Nuclei, SQLMap, FFUF, Hashcat) through MCP, gated on explicit written authorization.