{"repo":"opena2a-org/hackmyagent","free":true,"listed":false,"github":"https://github.com/opena2a-org/hackmyagent","clone":"git clone https://github.com/opena2a-org/hackmyagent.git","description":"Metasploit for AI agents: scan, attack, and fix AI agents and MCP servers. Open source security toolkit.","language":"TypeScript","stars":38,"topics":["tool","agent-security","ai-agents","ai-security","llm-security","mcp","mcp-security","penetration-testing","prompt-injection","red-team"],"license":null,"category":"ai-agents","readme_excerpt":"HackMyAgent OpenA2A : CLI · HackMyAgent · Secretless · AIM · Browser Guard · DVAA Security scanner, red-team toolkit, and behavioural simulator for AI agents. Apache 2.0. Website · Demos · Discord Quick start No config files. No flags required. Exit code 1 if any critical or high finding fires. What it finds - 310 static checks across 69 categories (323 checks across 74 categories including the NanoMind semantic layer). Credentials, MCP configs, OpenClaw and NemoClaw, Unicode steganography, CVEs, governance, supply chain, memory and RAG poisoning, agent identity, sandbox escape. Run hackmyagent check-metadata for the live list. - 29 NanoMind semantic checks. Every artifact (skill, MCP config, SOUL.md, system prompt) compiles into an Abstract Security Tree. The seven AST analyzers run against the tree: capability , credential , governance , scope , prompt , code , stego . Pattern matching misses undeclared capabilities, constraint weakness, scope mismatches, and scanner-evasion attempts. AST queries catch them. (This 29 is the fixed catalog of semantic checks. The Checks line in scan output — e.g. 12 semantic (NanoMind AST) above — reports the number of artifacts compiled in that particular run, not this catalog size.) - 164 adversarial payloads across 16 categories. Prompt injection, jailbreak, data exfiltration, capability abuse, context manipulation, MCP and A2A exploitation, memory weaponisation, context window, supply chain, tool shadow, parser differential, persistent ag","default_branch":null,"files":null,"tree":[],"storefront":"/r/opena2a-org","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/opena2a-org/hackmyagent/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}