Hit our first milestone today — Shai-Hulud 2.0 Detector just crossed 100 ⭐ on GitHub! What started as a small effort to help teams detect Shai-Hulud-style supply chain abuse is now getting real traction from the community.
Onwards and upwords ! https://t.co/KkR19GCW1x
AI Security Tools - November 2025
🧰 awesome-claude-skills - Curated Claude Skills collection with a Security & Systems section wiring Claude into web fuzzing, MCP hardening, and security automation workflows. ⭐️5.5k https://t.co/87I4AtOYnI by @composiohq - @prathitjoshi_, @Evyatar_Bluzer, @LeoVS09, Hong Cing Chen
🧰 IoT HackBot - IoT security toolkit combining Python CLI tools and Claude Code skills for automated discovery, firmware analysis, and exploitation-focused testing of IoT devices. ⭐️339 https://t.co/MyMN08DED8 by Brown Fine Security - @nmatt0
🧰 PatchEval - Benchmark for evaluating LLMs and agents on patching real-world vulnerabilities using Dockerized CVE testbeds and automated patch validation. ⭐️138 https://t.co/C3B7BIRlW5 by @BytedanceTalk - Jun ZENG, Zichao Wei, Shiqi Zhou
🧰 VulnRisk - Open-source vulnerability-risk assessment platform providing transparent, context-aware scoring beyond CVSS — ideal for local development and testing. ⭐️84 https://t.co/JPbIG4owcd
🧰 Wazuh-MCP-Server - Exposes Wazuh SIEM and EDR telemetry via Model Context Protocol so LLM agents can run threat-hunting and response playbooks against real data. ⭐️83 https://t.co/ShAFVop119 by @GensecAI
🧰 mcp-checkpoint - Continuously secures and monitors Model Context Protocol operations through static and dynamic scans, revealing hidden risks in agent-tool communications. ⭐️81 https://t.co/iFiZ4zJGs3 by @Aira_Security
🧰 ai-reverse-engineering - AI-assisted reverse engineering tool letting an MCP-driven chat interface orchestrate Ghidra to analyze binaries for security research. ⭐️42 https://t.co/VJoJTt7Pcd by @TIIuae - @biniamfisseha
🧰 whisper_leak - Research toolkit showing how encrypted, streaming LLM conversations leak prompt information via packet sizes and timing; includes capture, training, and benchmark pipeline. ⭐️42 https://t.co/yrQO79ZZCF by @yo_yo_yo_jbo
🧰 AI / LLM Red Team Field Manual & Consultant’s Handbook - Red-team playbook and consultant’s guide with attack prompts, RoE/SOW templates, OWASP/MITRE mappings, and testing workflows. ⭐️26 https://t.co/3fkvi2mGFG by @PenTestThor
🧰 LLMGoat - Deliberately vulnerable LLM lab for practicing and understanding OWASP Top 10 LLM vulnerabilities. ⭐️36 https://t.co/JKYChQ4bwy by @SECFORCE_LTD - @thelicato, António Quina, Rodrigo Fonseca
🧰 Reversecore_MCP - Security-first MCP server empowering AI agents to orchestrate Ghidra, Radare2, and YARA for automated reverse engineering. ⭐️25 https://t.co/io9eURhLKj
🧰 system-prompt-benchmark - Testing harness that runs LLM system prompts against 287 prompt-injection, jailbreak, and data-leak attacks using an Ollama-based judge. ⭐️3 https://t.co/ykZJ02MZWn by @KazKozDev
🧰 ctrl-alt-deceit - Extends MLEBench with sabotage tasks and monitoring tools to evaluate LLM agents that tamper with code, benchmarks, and usage logs. ⭐️3 https://t.co/Lyr3t5Fkrz by @apolloresearch@Teun_vd_Weij
🧰 SOC-CERT AI Helper - Chrome extension using Gemini Nano and KEV-backed CVE enrichment to detect and prioritize web threats in-browser. ⭐️1 https://t.co/qqpvB2XdEF by joupify
🧰 aifirst-insecure-agent-labs - Chatbot agent exploit lab for practicing prompt injection, system-prompt extraction, and guardrail bypass with NeMo/regex guardrails. ⭐️1 https://t.co/d9aCTEpA93 by @trailofbits - @willvandevanter
🧰 llm-security-framework - Security framework for AI-assisted development with tiered checklists, threat models, and docs to harden small AI projects quickly. ⭐️0 https://t.co/dptVnbFoem by Anna Blume
Shai-Hulud 2.0 Detector started as a response to a massive npm supply chain attack. Now it's a community-powered security tool with contributions from devs worldwide. Scan your repos. Protect your secrets. Stay safe. Free. Open source. One YAML line. https://t.co/0wY6VIyWQ9
75 ⭐️and growing on Shai-Hulud 2.0 Detector!
A free GitHub Action protecting devs from the npm supply chain attack . One line in your workflow. Zero compromised dependencies.
https://t.co/jHixUpJmjc
#opensource
Shai-Hulud 2.0 Detector is now on GitHub Marketplace! Protect your projects from the npm supply chain attack
✅ 790+ compromised packages
✅ Malicious script detection
✅ SARIF reports for Security tab
Free & open source.
https://t.co/0wY6VIyWQ9 @wbfoss
I prefer self-hosted AgentBuilders.
Because control > convenience.
I want to know where the prompts live, who can see the logs, and how the data flows. When agents start touching code, infra, or customer data.
Self-hosting isn’t a choice . It’s posture.
Calling #Python developers & #Wazuh admins! The Wazuh- #MCP-Server project is solid and running — but we’re looking to take it further. We need contributors, testers & real-world use cases.
🛠️ Help us improve it: 👉 https://t.co/AkOTrsAFcj #GenAI#Claude
What if instead of teaching AI about your protocol every time, it already knew? 🧵 Built the MCP Developer SubAgent - 8 specialized AI agents that understand Model Context Protocol from day one. The results are wild... https://t.co/ZtxEHr4LWa @GithubProjects
The latest Wazuh-MCP-Server v2.1.0 lets you query your Wazuh data using #Claude Desktop , etc.
Now supports 29+ tools: CVE checks, agent health and more.
🔗 https://t.co/3j2hc3DDSN #Wazuh#LLM#MCP#OpenSource
Hey @wazuh — we’ve built an open-source Wazuh MCP Server to integrate Model Context Protocol into Wazuh for GenAI capabilities.
Would love your help in reaching the Wazuh community for testing, feedback & contributions!
🔗 https://t.co/3j2hc3D63f
This N8N Youtube Agent generated $100k in 60 days
While you're still brainstorming titles and editing videos manually…
This AI Agent is pulling video prompts from Google Sheets, generating videos with Google Veo3, writing SEO titles using GPT-4o, uploading to YouTube, and updating your spreadsheet without you touching a thing.
It doesn’t just automate, It becomes your 24/7 content production machine
Here’s what this N8N beast does:
- Reads video prompts directly from Google Sheets
- Uses Veo3 to generate high-quality AI videos
- Auto-creates click-worthy titles with GPT-4o
- Waits, checks status, and processes completion hands-free
- Stores finished videos in Google Drive for backup
- Uploads to YouTube with proper metadata, no extra tools needed
- Updates the sheet with both video file and YouTube link
- Scales infinitely just keep adding prompts
- Requires ZERO code to run
This isn’t Zapier + CapCut + human VAs duct-taped together.
It’s a full-stack, API-first, YouTube machine powered by N8N.
While others pay $20K+ for similar systems, you'll own this forever with zero fees.
Just import the JSON files into your N8N instance and watch it work.
If you’re tired of content bottlenecks and want a truly hands-off YouTube engine…
This is the cheat code.
Comment “N8N” + RT + Like
I’ll DM you the full N8N workflow
(Must be following)
Or keep wasting hours editing thumbnails while someone else gets 100K views sleeping
Turn your #SIEM into an AI storyteller! #Wazuh-#MCP-Server pipes live Wazuh alerts into any LLM via MCP so models can triage threats for you. Looking for #infosec devs & blue-teamers to break, tweak & star it 👉 https://t.co/3j2hc3D63f #OpenSource#CyberSecurity