Top AI Repos — open-source AI, indexed and scored
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Top AI Repos tracks AI repositories on GitHub and answers two different questions about each one: is it moving right now, and would you bet a product on it.
Turn any LLM into an autonomous pentester. You define the scope, the agent does the work, you review the findings.
| Date | Stars |
|---|---|
| 2026-07-31 | 458 |
| 2026-08-06 | 464 |
Today
+6 stars today
This week
— stars this week
This month
— stars this month
Momentum
29.0
growth rate 0.00%/day
<p align="center"> <img src="./assets/banner1.png" alt="AIDA Banner" width="100%"> </p> <h1 align="center">AI-Driven Security Assessment</h1> <h3 align="center">Autonomous Pentesting Agent</h3> <p align="center"> An agent that runs full security assessments end-to-end.<br> You define the scope. You review the findings. </p> <p align="center"> <a href="#quick-start">Quick Start</a> • <a href="#what-it-does">What It Does</a> • <a href="Docs/INSTALLATION.md">Installation</a> • <a href="Docs/USER_GUIDE.md">User Guide</a> • <a href="Docs/MCP_TOOLS.md">Agent Tools</a> • <a href="https://discord.gg/RVJTWtkVA2">Discord</a> </p> <p align="center"> <img src="https://img.shields.io/badge/License-AGPL_v3-blue" alt="License"> <img src="https://img.shields.io/badge/Agent-Autonomous-red" alt="Autonomous"> <img src="https://img.shields.io/badge/Models-Claude%20%7C%20Gemini%20%7C%20GPT%20%7C%20Any-green" alt="Models"> <img src="https://img.shields.io/badge/Version-1.1.0-purple" alt="Version"> <a href="https://github.com/Vasco0x4/AIDA/stargazers"><img src="https://img.shields.io/github/stars/Vasco0x4/AIDA?style=flat&label=Stars&color=gold" alt="GitHub Stars"></a> <a href="https://discord.gg/RVJTWtkVA2"><img src="https://img.shields.io/badge/Discord-Join%20Community-5865F2?logo=discord&logoColor=white" alt="Discord"></a> </p> --- AIDA turns any LLM into an autonomous pentester capable of assessing web applications, APIs, and infrastructure. The agent reasons, understands application logic, executes commands in an isolated container, and documents every finding with the commands used. --- <p align="center"> <img src="./assets/view4.png" alt="AIDA Dashboard" width="800"> </p> --- ## Real Results Claude + AIDA isn't just talk. It produces results that end up in CVE databases. | ID | Severity | Project | Description | |----|----------|---------|-------------| | [CVE-2026-49869](https://www.cve.org/CVERecord?id=CVE-2026-49869) |  | [kestra-io/kestra](https://github.com/kestra-io/kestra) | Unauthenticated RCE via auth bypass + OS command injection (CWE-78/184/287/918) | | [CVE-2026-50189](https://www.cve.org/CVERecord?id=CVE-2026-50189) / [GHSA-xfvv-ggvq-pchh](https://github.com/appsmithorg/appsmith/security/advisories/GHSA-xfvv-ggvq-pchh) |  | [appsmithorg/appsmith](https://github.com/appsmithorg/appsmith) | RCE via newline injection in env variable endpoint | | [CVE-2026-32034](https://www.cve.org/CVERecord?id=CVE-2026-32034) |  | [openclaw/openclaw](https://github.com/openclaw/openclaw) | Insecure HTTP permits hijacking | | [CVE-2026-49979](https://www.cve.org/CVERecord?id=CVE-2026-49979) / [GHSA-vvxf-f8q9-86gh](https://github.com/appsmithorg/appsmith/security/advisories/GHSA-vvxf-f8q9-86gh) |  | [appsmithorg/appsmith](https://github.com/appsmithorg/appsmith) | SSRF via SMTP test endpoint — internal port scanning | *More under responsible disclosure — awaiting publication.* --- ## What It Does AIDA was built to give your AI everything a pentester needs to work. **A fully equipped execution environment.** A Docker container loaded with Linux pentesting tools — nmap, sqlmap, ffuf, nuclei, and anything else it needs. If a tool is missing, the agent installs it. **Custom exploitation via Python.** The agent generates and executes Python scripts on the fly — custom payloads, encoding tricks, protocol quirks, or any logic that off-the-shelf tools can't handle. **Burp-level HTTP control.** The agent sends and manipulates HTTP requests directly — headers, cookies, body, auth tokens. Stored credentials are auto-injected via placeholders. Same power as Burp Repeater, without the UI overhead. **A persistent notebook.** The agent logs what it knows about
Excerpt of 9,094 characters
Read on GitHubWould you bet a product on this? Bounded 0–100 and slow moving.
matched fp:bb919986182e381a, llm:Topics: ai, ai-powered, claude, llm, pentesting, security-tools, vulnerability-assessment; Description: 'Turn any LLM into an autonomous pentester. You define the scope, the agent does the work, you review the findings.'
matched fp:bb919986182e381a, llm:Topics: ai, ai-powered, claude, llm, pentesting, security-tools, vulnerability-assessment; Description: 'Turn any LLM into an autonomous pentester. You define the scope, the agent does the work, you review the findings.'
matched fp:bb919986182e381a, llm:Topics: ai, ai-powered, claude, llm, pentesting, security-tools, vulnerability-assessment; Description: 'Turn any LLM into an autonomous pentester. You define the scope, the agent does the work, you review the findings.'