🔒 安全工具 — Top 10 AI Agent 工具
渗透测试、漏洞扫描、代码审计、密钥管理——让 AI 帮你做安全自检。适合开发者日常安全左移、运维合规审查,也适合安全工程师加速日常重复工作。
共收录 318 个工具 · 显示评分最高 10 个
usestrix/strix
精选PythonOpen-source AI penetration testing tool to find and fix your app’s vulnerabilities.
KeygraphHQ/shannon
精选TypeScriptShannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
npx @keygraph/shannon setuporaios/serena
精选PythonA powerful MCP toolkit for coding, providing semantic retrieval and editing capabilities - the IDE for your agent
vxcontrol/pentagi
精选GoFully autonomous AI Agents system capable of performing complex penetration testing tasks
SWE-agent/SWE-agent
精选PythonSWE-agent takes a GitHub issue and tries to automatically fix it, using your LM of choice. It can also be employed for offensive cybersecurity or competitive coding challenges. [NeurIPS 2024]
NVIDIA/SkillSpector
精选PythonSecurity scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills befo
docker run --rm -v "$PWD:/scan" skillspector scan ./my-skill/ --no-llmmillionco/react-doctor
精选TypeScriptYour agent writes bad React. This catches it
NVIDIA/OpenShell
精选RustOpenShell is the safe, private runtime for autonomous AI agents.
uv add openshell0x4m4/hexstrike-ai
精选PythonHexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug boun
pip3 install -r requirements.txtfirerpa/lamda
精选PythonAndroid Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida, proxy/VPN/frp/P2P networking, MCP/Agent, 160+ APIs, designed
💡 如何选择合适的 安全工具 工具?
评分是怎么算的?+
Trove 的评分包含 4 个维度:文档质量(Doc)、代码质量(Code)、社区活跃度(Community)和近期更新(Activity),总分 25 分,并划分为精选(≥20)、已验证(≥12.5)、社区(<12.5)三档。
如何选择适合自己的工具?+
先看 tier(精选/已验证优先),再看 stars 和近期更新时间,最后看 install_hint 确认安装方式是否符合你的环境(npm/pip/go 等)。
这些工具支持哪些 AI 平台?+
大多数工具以 MCP 协议为标准,兼容 Claude、OpenClaw、Codex、Cursor 等主流 AI 平台。部分工具还提供 OpenAI Function / LangChain Tool 格式。
如何把自己的工具上榜?+
在 GitHub 发布你的工具,带上相关 topic(如 mcp-server、ai-agent-skills),Trove 的爬虫会自动收录并评分。也可以到 opentrove.ai/publish 主动提交。