Skip to content
@gensecaihq

GenSecAI

A non-profit community using generative AI to defend against AI-powered attacks, building open-source tools to secure our digital future from emerging AI

GenSecAI - Securing the GenAI Future ️

GitHub Organization Website Non-Profit Location

A global community of security researchers, developers, and enthusiasts building open-source tools to secure generative AI applications and infrastructure.


Our Mission

GenSecAI is a non-profit community dedicated to using generative AI to defend against AI-powered attacks. We build open-source tools to secure our digital future from emerging AI threats, making AI security accessible to everyone.


Featured Projects

Shai-Hulud 2.0 Detector

Repo Stars Issues Language

Detect npm packages compromised in the Shai-Hulud 2.0 supply-chain attack with a battle-tested GitHub Action and CLI.

  • Features: Lockfile and repo scanning, SARIF reports, CI/CD integration, allowlist support
  • Tech Stack: TypeScript, GitHub Actions, Node.js
  • Target: Supply chain security for npm projects

react2shell-scanner

Repo Stars Issues Language

Security scanner for CVE-2025-55182 – a critical RCE vulnerability in React Server Components.

  • Features: Scans npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs; auto-fix mode; SARIF output; GitHub Actions; Vercel runtime protection middleware
  • Tech Stack: TypeScript, Node.js, GitHub Actions
  • Use Case: React2Shell exposure detection and mitigation

Wazuh-MCP-Server

Repo Stars Issues Language

AI-powered security operations with Wazuh SIEM + Claude Desktop.

Transform your SOC with natural language threat detection, automated incident response & compliance monitoring.

  • Features: Real-time monitoring, ML anomaly detection, conversational security analysis
  • Tech Stack: Python, Wazuh, MCP Protocol
  • Status: Production-ready

🛡️ KubeKavach

Repo Stars Issues Language

Developer-first Kubernetes security scanner with instant pod replay.

Debug production issues locally in seconds with AI-powered explanations.

  • Features: CERT-IN friendly posture, instant pod replay, AI-guided diagnostics
  • Tech Stack: Go, Kubernetes, AI/ML
  • Use Case: Kubernetes security scanning and compliance

MCP Security Command Center (mcpscc)

Repo Stars Issues Language

“The Trivy of MCP security” – a Security Command Center for Model Context Protocol (MCP) servers.

  • Features: Detects prompt injection, tool poisoning, secret exposure, and misconfigurations; OWASP MCP Top 10 coverage; SARIF/JSON/HTML/PDF outputs
  • Tech Stack: Python, FastAPI, MCP client + YARA rules
  • Use Case: Continuous security scanning of MCP servers and CI/CD pipelines

pfSense-MCP-Server

Repo Stars Issues Language

Manage pfSense firewalls using natural language through AI assistants like Claude Desktop.

  • Features: 5-level RBAC, REST/XML-RPC/SSH support, built-in compliance checks
  • Tech Stack: Python, pfSense, MCP Protocol
  • Benefits: Natural language firewall management

GenAI API Pentest Platform

Repo Stars Issues Language

API security testing tool that leverages multiple Large Language Models (LLMs) to perform intelligent, context-aware API security assessments.

  • Features: Multi-LLM support, context-aware testing, automated vulnerability discovery
  • Tech Stack: Python, multiple LLM providers
  • Target: API security testing

Ubuntu Security Hardening Script

Repo Stars Issues Language

Automates the scanning process using OpenSCAP Security Guide to harden Ubuntu systems, aligning with DISA-STIG-style compliance.

  • Features: Ubuntu 24.04 LTS minimum, opinionated hardening, compliance-friendly profiles
  • Tech Stack: Shell scripting, OpenSCAP
  • Purpose: System hardening and compliance

RDAP Lookup

Repo Stars Issues Language

Modern web application utilizing Next.js App Router to perform robust RDAP queries.

  • Features: Domain/IP/ASN/entity lookup, modern UI, security-centric checks
  • Tech Stack: TypeScript/JavaScript, Next.js
  • Benefits: Structured registration & domain intelligence data

⚠️ MCP Poisoning PoC

Repo Stars Issues Language

Demonstrates various MCP poisoning attacks affecting real-world AI agent workflows.

  • Purpose: Security research and awareness
  • Target: AI agent and tool security
  • Type: Proof of Concept

CVE-2024-3094 Vulnerability Checker & Fixer

Repo Stars Issues Language

Shell scripts to identify and remediate installations of xz-utils affected by CVE-2024-3094.

  • Features: Detection, downgrade/rollback options, Ansible playbook
  • Use Case: Fleet-wide validation during critical backdoor incidents

Sonicwall-MCP-Server

Repo Stars Issues Language

A comprehensive MCP server for analyzing SonicWall firewall logs from SonicOS 7.x and 8.x.

  • Features: Intelligent log analysis, threat detection, security insights via MCP tools
  • Tech Stack: TypeScript, MCP, SSE/HTTP transport
  • Compatibility: SonicOS 7.x and 8.x

Claude-Code-Subagents-Collection

Repo Stars Issues License

A meticulously crafted collection of 75+ specialized Claude Code sub-agents for comprehensive software development support.

  • Features: Curated sub-agents, accuracy-focused, efficiency-optimized
  • Tech Stack: Claude Code framework
  • Purpose: Enhanced AI-assisted development

️MCP-Developer-SubAgent

Repo Stars Issues Language

Specialized framework for MCP development featuring 8 Claude Code sub-agents and production-ready templates.

  • Features: Security hooks, FastMCP server templates, markdown-driven agents
  • Tech Stack: Python, FastMCP, MCP Protocol
  • Benefits: Immediate MCP development assistance

LetsEncrypt-IP-SSL-Manager

Repo Stars Issues Language

Simplifies obtaining and managing Let’s Encrypt IP certificates with automatic renewal and comprehensive validation.

  • Features: Automatic renewal, robust validation, logging
  • Tech Stack: Shell scripting, Let’s Encrypt/Certbot
  • Use Case: SSL certificate management for IP-only endpoints

Nginx-SSL-Automation-LetsEncrypt

Repo Stars Issues Language

Simple shell script for automating the installation and renewal of Let’s Encrypt SSL certificates on Linux servers using Nginx.

  • Features: Automated installation, renewal, Nginx integration
  • Tech Stack: Shell scripting, Nginx, Let’s Encrypt
  • Purpose: Simplify SSL certificate management

Community & Collaboration

We believe in the power of community-driven security research.
Our projects are:

  • 100% Open Source – All tools are freely available
  • 🌍 Globally Collaborative – Contributors from around the world
  • 🧪 Research-Focused – Advancing the state of AI and security
  • 🧱 Practical & Production-Ready – Real-world, deployable solutions

Getting Started

For Security Professionals

  1. Browse our repositories for tools that match your needs
  2. Check individual project documentation for installation and deployment guides
  3. Join our community discussions to share insights and get help

For Contributors

  1. Fork the repository you’re interested in
  2. Create a feature branch (git checkout -b feature/AmazingFeature)
  3. Commit your changes (git commit -m 'Add some AmazingFeature')
  4. Push to the branch (git push origin feature/AmazingFeature)
  5. Open a Pull Request

Our Impact

  • 15+ Active Projects – Covering multiple areas of AI and security
  • Growing Community – Security researchers, developers, and enthusiasts
  • Global Reach – Contributors and users worldwide
  • Enterprise-Ready – Tools used in production environments

Resources


Why GenSecAI?

  1. AI-First Security – We leverage AI to defend against AI threats
  2. Open Source Philosophy – Democratizing AI security for everyone
  3. Practical Solutions – Production-ready tools, not just research
  4. Community Driven – Built by the community, for the community
  5. Compliance Focus – Tools designed with regulatory requirements in mind

License

Most of our projects are released under open-source licenses (MIT, Apache 2.0, etc.).
Please check individual repositories for specific licensing information.


Support Our Mission

As a non-profit organization, we rely on community support to continue our work. You can help by:

  • ⭐ Starring our repositories
  • 🐛 Reporting bugs and suggesting features
  • 🧩 Contributing code and documentation
  • 📣 Spreading the word about our projects
  • ☁️ Supporting our infrastructure costs

Building a secure AI future, one commit at a time.
Made with ❤️ by the GenSecAI Community

Pinned Loading

  1. Wazuh-MCP-Server Wazuh-MCP-Server Public

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PCI DSS, GDPR, HIPAA, NIST CSF, ISO 27001) and active response…

    Python 232 63

  2. mcp-poisoning-poc mcp-poisoning-poc Public

    This repository demonstrates a variety of **MCP Poisoning Attacks** affecting real-world AI agent workflows.

    Python 15 5

  3. Ubuntu-Security-Hardening-Script Ubuntu-Security-Hardening-Script Public

    This script automates the scanning process using the OpenSCAP Security Guid to hardening Ubuntu systems, aligning with DISA-STIG compliance for Ubuntu 24.04. LTS minimum. It includes a range of sec…

    Shell 107 15

  4. genai-api-pentest-platform genai-api-pentest-platform Public

    The GenAI API Pentest Platform is a API security testing tool that leverages multiple Large Language Models (LLMs) to perform intelligent, context-aware API security assessments. Unlike traditional…

    Python 18 7

  5. LetsEncrypt-IP-SSL-Manager LetsEncrypt-IP-SSL-Manager Public

    This tool simplifies the process of obtaining and managing Lets' Encrypt IP certificates with automatic renewal, comprehensive validation, and user ready features.

    Shell 6 2

  6. Sonicwall-MCP-Server Sonicwall-MCP-Server Public

    A comprehensive Model Context Protocol (MCP) server for analyzing SonicWall firewall logs from SonicOS 7.x and 8.x. This server provides intelligent log analysis, threat detection, and security ins…

    TypeScript 8 2

Repositories

Showing 10 of 20 repositories
  • Wazuh-MCP-Server Public

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PCI DSS, GDPR, HIPAA, NIST CSF, ISO 27001) and active response. Connect Claude or any LLM to your SOC. OAuth 2.1, RBAC, multi-cluster, air-gap ready.

    gensecaihq/Wazuh-MCP-Server's past year of commit activity
    Python 232 MIT 63 1 8 Updated Sep 15, 2026
  • Shai-Hulud-2.0-Detector Public

    GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

    gensecaihq/Shai-Hulud-2.0-Detector's past year of commit activity
    TypeScript 150 MIT 33 0 1 Updated Sep 15, 2026
  • pfsense-mcp-server Public

    Model Context Protocol (MCP) server for pfSense firewall management. Control firewall rules, VPNs, DNS, DHCP and diagnostics in natural language from Claude Desktop, Claude Code or any MCP client — 333 wire-format-verified tools for the pfSense REST API, with safety guardrails, config backup and rollback on every change.

    gensecaihq/pfsense-mcp-server's past year of commit activity
    Python 97 MIT 19 1 5 Updated Aug 28, 2026
  • mcpscc Public

    Security for AI agents & MCP — map how MCP servers, skills, and memory chain into exposure paths. Toxic-flow detection, cross-surface graph, drift & policy-as-code. Local-only, no telemetry.

    gensecaihq/mcpscc's past year of commit activity
    Python 6 Apache-2.0 1 0 0 Updated Aug 9, 2026
  • Wazuh-Autopilot Public

    Autonomous AI SOC for Wazuh SIEM — 11 security-expert agents triage, correlate, investigate and plan responses 24/7, every action gated by two-tier human approval. Runs on OpenClaw, Hermes or NVIDIA NemoClaw; any LLM, self-hosted vLLM, or fully air-gapped Ollama. Evidence packs, SOC KPIs, Slack approvals.

    gensecaihq/Wazuh-Autopilot's past year of commit activity
    JavaScript 53 MIT 16 4 0 Updated Aug 8, 2026
  • Ubuntu-Security-Hardening-Script Public

    This script automates the scanning process using the OpenSCAP Security Guid to hardening Ubuntu systems, aligning with DISA-STIG compliance for Ubuntu 24.04. LTS minimum. It includes a range of security enhancements and configurations designed to strengthen the security posture of Ubuntu servers.

    gensecaihq/Ubuntu-Security-Hardening-Script's past year of commit activity
    Shell 107 MIT 15 0 0 Updated Aug 8, 2026
  • kubekavach Public

    Developer-first K8s security scanner with instant pod replay. Debug prod issues locally in seconds. AI-powered explanations. CERT-IN compliant for Indian orgs.

    gensecaihq/kubekavach's past year of commit activity
    TypeScript 4 0 0 34 Updated Feb 17, 2026
  • ocsas Public

    OCSAS is a security checklist and hardening guide for OpenClaw users. It helps you deploy OpenClaw safely by telling you exactly what settings to configure and how to verify your setup is secure.

    gensecaihq/ocsas's past year of commit activity
    Ruby 3 Apache-2.0 0 0 0 Updated Jan 30, 2026
  • ossasai Public

    OSSASAI is a security framework for AI agents — the bots that can run commands, browse the web, and access your files. It tells you what security controls to look for and how to verify they're working.

    gensecaihq/ossasai's past year of commit activity
    Shell 1 Apache-2.0 0 0 0 Updated Jan 30, 2026
  • react2shell-scanner Public

    Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Auto-fix, SARIF output, GitHub Actions, Vercel integration, and runtime protection middleware.

    gensecaihq/react2shell-scanner's past year of commit activity
    TypeScript 58 MIT 7 0 0 Updated Dec 7, 2025

People

This organization has no public members. You must be a member to see who’s a part of this organization.