
Scanners-Box is a heavily curated open-source index of security scanners spanning AI agents, red teaming, malware analysis and compliance, intended as a reference catalog for authorized assessments and research.
| Tool | We5ter/Scanners-Box — curated open-source collection of security scanners and automation tooling |
| Category | Curated tool directory / security resource index |
| Primary Use | Discovering vetted open-source scanners by domain — AI agent security, redteam/blueteam, malware analysis, static-analysis, smart contracts — to build assessment toolchains |
| Safe Use | Reference catalog for authorized penetration tests, internal security audits, lab environments and defensive research; operators must separately verify each linked tool's license and scope before use |
| Telemetry Note | As a static README-based index the repo itself generates no telemetry; the linked scanners each have their own network footprint, so defenders should evaluate individual tools' traffic signatures separately |
We5ter/Scanners-Box sits in that peculiar genre of security repository that is itself a tool: a meticulously organized catalog of open-source scanners, maintained with roughly nine thousand stars and a bilingual README available in English, Simplified Chinese and Spanish. Unlike a single-purpose scanner, its value lies in taxonomy — it maps the offensive and defensive tooling landscape into categories a professional can navigate quickly, from subdomain enumeration to smart-contract auditing. What makes the current iteration notable is how visibly the maintainers have pivoted toward AI, placing autonomous agents at the very top of the table of contents as an explicitly marked focus zone.
The AI section is the repository's clearest editorial statement. It is subdivided into AI Autonomous Cybersecurity Agents, LLM-Powered Vulnerability Scanners, Security Auditing for AI Agents & Apps, AI Agent Runtime Controls, Security Auditing for Agent Skills, and Autonomous Vulnerability Discovery and Remediation Skills. That granularity tells you the maintainers are tracking the agentic-security niche as a first-class discipline rather than an afterthought, and each entry carries shields-style badges showing the main language, last commit date, star count and license — a small but genuinely useful due-diligence signal when you are triaging whether a tool is alive.
The flagship entries in the autonomous-agents category illustrate what the curators consider mature. pentagi is described as a fully autonomous multi-agent pentesting system written in Go, running engagements inside an isolated Docker sandbox with twenty-plus bundled tools including nmap, metasploit and sqlmap, long-term memory, an optional Neo4j knowledge graph and a web console for human-in-the-loop monitoring. That description alone communicates the architectural pattern the field is converging on: containerized isolation, tool orchestration, persistent knowledge, and a supervision layer so an operator can watch what the agent is doing.
Around pentagi, the category spans a spectrum of approaches. Cairn is listed as a general-purpose state-space search engine validated on autonomous pentesting, with no predefined roles or workflows — purely goal-driven pathfinding, an interesting abstraction that treats exploitation as graph traversal. shannon from KeygraphHQ is a white-box AI pentester for web apps and APIs that reads source code, identifies attack vectors and executes exploits pre-production, positioning itself for shift-left pipelines. CyberStrikeAI is an AI-native platform in Go integrating over a hundred tools with role-based testing, a skills system and a built-in lightweight C2 framework explicitly framed for authorized engagements.
The LLM-Powered Vulnerability Scanners subsection is shorter but strategically interesting. nano-analyzer from weareaisle is billed as a minimal LLM-powered zero-day scanner — minimalism being a deliberate counterpoint to the heavyweight platforms above. deepsec from vercel-labs applies agent-driven review to entire large-scale repositories, surfacing long-lurking issues, while vigolium fuses agentic AI with native speed and modularity in Go. Read together, these three sketch a design debate: whether LLM scanners should be orchestrating external tools or reading code directly.
Perhaps the most practically valuable section for defenders is Security Auditing for AI Agents & Apps. garak is an LLM vulnerability scanner probing for hallucination, data leakage, prompt injection, misinformation, toxicity and jailbreaks — effectively a nessus-style checklist mindset applied to model behavior. rebuff from protectai defends AI applications against prompt injection, and LLMFuzzer provides a fuzzing framework for large language models. Tencent/AI-Infra-Guard covers the infrastructure layer, combining AI infrastructure vulnerability scanning, MCP server risk detection and LLM security assessment, which reflects how quickly MCP has become an audit surface in its own right.
One of the most specific entries is agentshield, a TypeScript security auditor for AI agent configurations — particularly Claude Code setups. It scans for hardcoded secrets, permission misconfigurations, hook injection, MCP server risks and prompt injection vectors, packing 268 rules across 15 modules with a 0-100 score, auto-fix, CI gating and compliance mapping to SOC 2, PCI DSS and ISO 27001. For enterprise DevSecOps teams adopting agent tooling, that compliance mapping is the detail that turns a niche scanner into something a security governance program can actually consume.
Beyond the AI focus zone, the classic structure remains intact and expansive. The table of contents covers scanners for smart contracts, red team versus blue team tooling, mobile app package analysis, binary executable analysis, privacy compliance, subdomain enumeration and takeover, database SQL injection and brute force, weak credential enumeration for web targets, IoT hardware auditing, multiple types of cross-site scripting detection, enterprise sensitive information leak scanning, malware detection, middleware vulnerability assessment, special web vulnerability categories, dynamic and static code analysis, modular scanner frameworks, and APT detection. The breadth is the point — this is a map of the whole scanning domain, not a recommendation of one stack.
The repository's topic list corroborates this positioning with tags like apk-analysis, binary-analysis, devsecops, malware-analysis, smart-contracts, static-analysis, wifi-security and security-automation. There is no code to install here, so the operational footprint is essentially zero: consuming the resource means browsing the README on the master branch and following links to the individual upstream projects. That also means supply-chain responsibility is deferred — each linked scanner must be independently vetted for license, maintenance status and safety before it touches an engagement.
Several auxiliary projects hang off the repository. A Daily AI Tool Picks page hosted on GitHub Pages continuously surfaces AI agent tooling, and ScanCodex is advertised as an MCP server badge, implying the catalog can be queried by AI agents themselves — a slightly meta touch where the index becomes machine-consumable by the same agent ecosystem it catalogs. The auto-generated table of contents via doctoc and the per-entry commit-date badges suggest curation hygiene that many awesome-lists lack.
For authorized professionals, the sensible workflow is to treat Scanners-Box as a discovery and comparison layer: identify the category matching your engagement scope, shortlist candidates by language and maintenance recency, then validate each tool in a lab before deployment against systems you are contracted to test. The catalog explicitly frames offensive entries around authorized use, but the usual rule holds — the scope agreement, not the list, governs what you may run. As a documentary snapshot of where security automation is heading, with agentic tooling promoted from curiosity to headline category, this repository is worth periodic revisiting.
We5ter/Scanners-Box.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.