🔒 安全工具 — Top 10 AI Agent 工具

渗透测试、漏洞扫描、代码审计、密钥管理——让 AI 帮你做安全自检。适合开发者日常安全左移、运维合规审查,也适合安全工程师加速日常重复工作。

共收录 318 个工具 · 显示评分最高 10

1

usestrix/strix

精选Python

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Stars
100
2

KeygraphHQ/shannon

精选TypeScript

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

Stars
100
npx @keygraph/shannon setup
3

oraios/serena

精选Python

A powerful MCP toolkit for coding, providing semantic retrieval and editing capabilities - the IDE for your agent

Stars
100
4

vxcontrol/pentagi

精选Go

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

Stars
100
5

SWE-agent/SWE-agent

精选Python

SWE-agent takes a GitHub issue and tries to automatically fix it, using your LM of choice. It can also be employed for offensive cybersecurity or competitive coding challenges. [NeurIPS 2024]

Stars
100
6

NVIDIA/SkillSpector

精选Python

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills befo

Stars
100
docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llm
7

millionco/react-doctor

精选TypeScript

Your agent writes bad React. This catches it

Stars
100
8

NVIDIA/OpenShell

精选Rust

OpenShell is the safe, private runtime for autonomous AI agents.

Stars
100
uv add openshell
9

0x4m4/hexstrike-ai

精选Python

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug boun

Stars
100
pip3 install -r requirements.txt
10

firerpa/lamda

精选Python

Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida, proxy/VPN/frp/P2P networking, MCP/Agent, 160+ APIs, designed

Stars
100

💡 如何选择合适的 安全工具 工具?

评分是怎么算的?+

Trove 的评分包含 4 个维度:文档质量(Doc)、代码质量(Code)、社区活跃度(Community)和近期更新(Activity),总分 25 分,并划分为精选(≥20)、已验证(≥12.5)、社区(<12.5)三档。

如何选择适合自己的工具?+

先看 tier(精选/已验证优先),再看 stars 和近期更新时间,最后看 install_hint 确认安装方式是否符合你的环境(npm/pip/go 等)。

这些工具支持哪些 AI 平台?+

大多数工具以 MCP 协议为标准,兼容 Claude、OpenClaw、Codex、Cursor 等主流 AI 平台。部分工具还提供 OpenAI Function / LangChain Tool 格式。

如何把自己的工具上榜?+

在 GitHub 发布你的工具,带上相关 topic(如 mcp-server、ai-agent-skills),Trove 的爬虫会自动收录并评分。也可以到 opentrove.ai/publish 主动提交。

安全工具 - 最佳 AI Agent 工具 Top 10 | Trove