Scanners-Box Security Arsenal
A curated open-source index of security tooling for hackers, enterprises and AI agents.
- Source repo
- We5ter/Scanners-Box
- Stars
- ★ 9.1k
- Last updated
- 13d ago
- License
- NOASSERTION
- FA score
- 19/100 · Major gaps
At a glance
- How it runs
- Works with
- Portable with changes
- Cost
- Free, no paid service needed
- Setup effort
- Low · running in minutes
- You'll need
- Typical use
- A security team preparing an AI agent red-team exercise browses the pinned "AI & Autonomous Agents" zone to shortlist LLM vulnerability scanners, prompt-injection defenses and agent-skill checkers.
- Not a fit if
- Teams that need an out-of-the-box, fully documented executable — this repo only indexes tools and displays badges, with no runnable code.
- Users expecting official maintenance, version guarantees and security audits — every listed tool is a third-party project with varying quality and maintenance.
- Teams needing a Chinese or non-English UI — listed tools are predominantly documented in English.
- Source review
- 19/100 · Major gaps 7 safety controls not found
What does this agent do, and when should you use it?
Scanners-Box (We5ter/Scanners-Box) is an index repository on GitHub, not a runnable scanner: it collects several hundred third-party security projects into a Markdown taxonomy with shields.io badges for main language, last commit, stars and license. Its sections span AI autonomous cybersecurity agents, LLM-powered vulnerability scanners, security auditing for AI agents and apps, AI agent runtime controls, agent-skill scanning, smart-contract scanners, red/blue team tooling, mobile package analysis, binary executables analysis, privacy compliance, subdomain enumeration and takeover, SQL injection, weak credential enumeration, IoT auditing, XSS detection, enterprise leak scanning, malware detection, middleware assessment, dynamic/static code analysis, modular scanning frameworks and APT detection. The header badges link out to two author-adjacent properties, Scanners-Box Daily AI Tool Picks and the ScanCodex MCP Server. The repository carries a NOASSERTION license and provides navigation only; installation, runtime and license terms for each tool live in the respective upstream repositories. It ships no dependency manifest, tests, releases or executable code of its own.
The repository organizes a large three-level Markdown list: top-level headings such as "AI Autonomous Cybersecurity Agents", "Red Team vs Blue Team" and "Subdomain Enumeration or Takeover"; sub-headings such as "Supply Chain Analysis(SCA)", "Container and Cluster" and "Wireless Pentest"; and entries that pair a third-party GitHub URL with a one-line English description plus four badge images (MainLanguage, last commit, stars, license). A doctoc-generated table of contents enables in-page jumps to each section. It performs no scanning, opens no target files, exposes no API and produces no reports; the only interactive output is badge and link navigation on the rendered GitHub page.
- A security team preparing an AI agent red-team exercise browses the pinned "AI & Autonomous Agents" zone to shortlist LLM vulnerability scanners, prompt-injection defenses and agent-skill checkers.
- A DevSecOps owner building a pipeline looks through the red/blue team and code-analysis sections to compare container, Kubernetes and supply-chain scanners before evaluating each upstream project on its own.
- A penetration tester doing external asset discovery uses the subdomain enumeration and takeover section to find enumeration, takeover-detection and fingerprinting tools.
- A mobile security engineer hunting for APK static analysis or malware scoring picks candidates such as apkleaks, quark-engine or APKHunt from the mobile packages section.
- A blockchain researcher scanning Solidity or EVM bytecode checks the smart-contract section for mythril, oyente, securify2 or MAIAN.
- A technical writer or instructor needs a domain-organized list of security projects as source material for a course or article and uses the taxonomy to locate relevant entries quickly.
How do you install or deploy this agent?
This is an index repository, so there is nothing to install: no package-manager command, service component or build step is documented in the README. The only meaningful local operation is cloning the Markdown files for offline reading. The README does not state any runtime requirements, dependency file, published package or install script; that information is genuinely absent and must be sourced elsewhere.
git clone https://github.com/We5ter/Scanners-Box.git
cd Scanners-BoxAfter cloning, read README.md, README_CN.md or README_ES.md. To actually run any listed tool, follow that upstream project's own installation documentation.
How do you use this agent?
The intended flow is search, jump, then install from upstream. Use the doctoc table of contents at the top of the README to reach a section — for example the AI Autonomous Cybersecurity Agents section — read each entry's description and badges, and follow the link to the third-party repository. The README defines no CLI entry point, API endpoint, configuration file or output format, so there is no canonical runnable snippet. The commands below only speed up local reading of the Markdown and are not an official interface:
# find entries by keyword in the cloned repo
grep -n -i "agent" README.md
# list every referenced GitHub repository link
grep -oE "https://github.com/[^ )]+" README.md | sort -uWhat are this agent's strengths and limitations?
- An unusually broad taxonomy for a single list: AI agent security, agent-skill scanning, containers, Kubernetes, wireless, mobile, binaries and smart contracts all sit in one navigable hierarchy.
- Every entry carries four shields.io badges — main language, last commit, stars and license — so a reader can gauge activity without opening each upstream repository.
- The AI zone is pinned first and split into six meaningful sub-areas: autonomous agents, LLM vulnerability scanners, agent/app auditing, runtime controls, skill auditing and autonomous remediation skills.
- Three README languages (English, Simplified Chinese, Spanish) plus a generated table of contents make the list usable across language backgrounds.
- The repository ships no executable code, dependency manifest, tests or releases, so it cannot be installed or run; every security capability lives in a third-party project.
- The license is marked NOASSERTION and each listed tool has its own terms, so commercial use or redistribution requires checking every upstream project individually.
- Inclusion criteria and ordering are not explained in the visible content, and many entries have only a single-sentence description, which is thin evidence for production suitability.
- Parts of the README are truncated in the available material (for example the tail of the subdomain enumeration section), so completeness of some categories cannot be verified.
How does this agent compare with similar options?
Within the README body, the named projects are listed items rather than alternatives to this repository — OWASP Amass, theHarvester, Sublist3r and subfinder appear as subdomain-enumeration entries, while ScanCodex (the author's MCP server) and Scanners-Box Daily AI Tool Picks are linked author-adjacent properties. The source does not name any competing index or curated-list repository, so no direct alternative is asserted here.
Key facts side by side with the most closely related agents.
| Agent | Source review | Form / cost | Stars | Updated | Language | Full support on |
|---|---|---|---|---|---|---|
| Scanners-Box Security Arsenal This agent | 19 · Major gaps | Web appFree | ★ 9.1k | 13d ago | — | — |
| RedAmon: Autonomous AI Red Team Framework | 48 · Major gaps | CLIFree + model costs | ★ 3k | 3d ago | Python | OpenAI API · Claude API |
| CyberStrike — Open-Source AI Penetration Testing & Red Team Platform | 43 · Major gaps | CLIFree + model costs | ★ 3.1k | today | TypeScript | — |
| CyberStrikeAI — AI-Native Cybersecurity Action System | 44 · Major gaps | CLIFree + model costs | ★ 7.6k | 1d ago | Go | OpenAI API · Claude API |
How does FollowAgents rate this agent?
Why each dimension lost points
The repository is essentially a README link list with no executable code, permission declarations, confirmation flows, or data-flow documentation, so least_privilege, user_confirmation, data_flow_transparency, sensitive_data_handling, dependency_security, external_effects, and rollback have no evidence and score 0. source_attribution scores 1: each entry gives a GitHub URL and badges, but the descriptive text is unsourced marketing copy and no inclusion criteria or review status is stated.
self_consistency scores 1: the TOC broadly matches the body, but the body is truncated mid-entry at vesta and badges are external dynamic images that may diverge from the static text. dependency_availability and failure_messages score 0: no dependency manifest, install script, or error-handling path exists to assess.
audience_and_scenarios scores 2: the README explicitly targets geeks, enterprises, and AI agents and organizes entries by scenario (AI agents, smart contracts, red/blue team), so the audience is clear. capability_boundaries scores 1: it states it is a tool matrix but never defines what it does not do, which tools it endorses, or whether anything was validated. trigger_precision scores 0: a list repository has no trigger or invocation surface. environment_fit scores 1: entries carry language badges but no runtime, version, or platform requirements.
information_architecture scores 2: a doctoc-generated TOC plus categorized headings gives complete navigation. install_notes scores 0: no installation or usage instructions at all. naming_stability scores 1: category headings are mostly stable but contain typos (Mutiple, Scannners, promp injection) that hurt searchability and citation consistency. examples_and_faq scores 1: only one-line entry descriptions, no usage examples or FAQ. known_limitations scores 0: no limitations, disclaimers, or unverified-content warnings. license scores 1: the LICENSE file contains the full CC BY-NC-ND 4.0 text, but repository metadata says NOASSERTION, and that license forbids derivatives and restricts commercial use, which sits awkwardly with an enterprise-facing tool matrix. versioning_changelog scores 0: no version number, no CHANGELOG. maintenance_responsibility scores 1: a publisher account and badges exist, but there is no maintenance commitment, cadence, or contact path, and the publisher identity is unverified.
output_usability scores 1: the output is a link list that is directly navigable but lacks filtering, scoring, or verification metadata. marginal_value scores 1: comparable open-source security tool lists are abundant; this repository's increment is mainly the AI-agent category, with no proprietary evaluation or integration. cost_benefit scores 1: reading cost is low, but users must still verify each tool's quality and safety themselves, so the payoff is uncertain.
claim_traceability scores 1: entries trace to specific GitHub repositories, but descriptive claims (e.g. 'fully autonomous', 'proof-based vulnerabilities') carry no supporting source. cross_source_corroboration scores 0: no second source, tests, or evaluation data inside the repository to cross-check. fact_inference_separation scores 1: the list format separates links from descriptions, but descriptions are not separated from facts, mixing marketing language with objective information.
- Not found in source: least-privilege scopingGrant only what the task needs: a dedicated account or read-only token, scoped to specific directories and repos.
- Not found in source: confirmation before actingTurn on (or add) a confirmation step before it acts, and try it in a sandbox or test environment before real data.
- Not found in source: data-flow disclosureWatch which external services it contacts (proxy or firewall logs) and keep sensitive data out until you know where it goes.
- Not found in source: sensitive-data handlingUse dedicated, low-privilege, revocable API keys — never production credentials — and keep secrets out of logs.
- Not found in source: dependency securityPin versions and run a dependency audit (npm audit, pip-audit) before installing; prefer running it in a container.
- Not found in source: disclosed external effectsEstablish which external systems it writes to, sends to or changes, and verify with test accounts or repos before production.
- Not found in source: rollback or recovery pathBack up first, or work on a git branch or snapshot, so its changes can be undone.
- This repository is a link list, not an executable agent product; no guarantees can be made about permissions, data flow, rollback, or dependency security, and every trust criterion scores 0 for lack of evidence.
- Entry descriptions are unsourced marketing claims and the body is truncated mid-entry at vesta, so list completeness is unverified; do not adopt the listed tools on this basis alone.
- The license is CC BY-NC-ND 4.0 (no derivatives, non-commercial) while repository metadata reports NOASSERTION; clarify the actual grant before any enterprise or commercial use.
- Publisher identity is unverified and there is no version number, CHANGELOG, or maintenance commitment, so update cadence and long-term availability cannot be judged.