gori — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by hahwul · MCP Server · ★ 102

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is gori safe to install? View the security audit →

About gori

Hack from the terminal. Installation • Usage • Documentation • Contributing gori (고리 — Korean for ring, link, loop) sits in the loop between your client and its target, capturing every request and response as a flow you can replay, fuzz, and scan across HTTP/1.1, HTTP/2, WebSocket, gRPC, and SSE, and intercept in flight on HTTP/1.1 and HTTP/2. Core assessment actions that cross surfaces use the same engines, and those workflows are also available through and MCP, so scripts and AI agents can drive the same engagement. The capability matrix names the protocol and surface limits explicitly. ![gori TUI — the History tab listing captured HTTP flows]

bugbountyclicrystalgorimcpmcp-servermitmpentestingproxysecurity

Quick Facts

Stars102
Forks14
LanguageCrystal
CategoryMCP Server
LicenseApache-2.0
Quality Score72.7851289189607/100
Open Issues13
Last Updated2026-09-21
Created2026-06-13
Platformscli, mcp
Est. Tokens~17k

Compatible Skills

These tools work well together with gori for enhanced workflows:

gori alternative? Top 6 similar tools

Looking for a gori alternative? If you're comparing gori with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Fray by dalisecurity · ⭐ 53

    AI-native security toolkit — fray go target.com scans everything. 7,800+ payloads, 98 WAF vendors, 42+ recon c

  • h1-brain by PatrikFehrenbach · ⭐ 333

    MCP server that connects AI assistants to HackerOne for bug bounty hunting

  • agentseal by AgentSeal · ⭐ 156

    Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply cha

  • powhttp-mcp by usestring · ⭐ 81

    MCP server enabling agents to debug HTTP requests better (using powhttp)

  • tengu by rfunix · ⭐ 58

    AI-powered penetration testing MCP server

  • bridle by neiii · ⭐ 433

    TUI / CLI config manager for agentic harnesses (Amp, Claude Code, Opencode, Goose, Copilot CLI, Crush, Droid)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Frequently Asked Questions

What is gori?

gori is A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.. It is categorized as a MCP Server with 102 GitHub stars.

What programming language is gori written in?

gori is primarily written in Crystal. It covers topics such as bugbounty, cli, crystal.

How do I install or use gori?

You can find installation instructions and usage details in the gori GitHub repository at github.com/hahwul/gori. The project has 102 stars and 14 forks, indicating an active community.

What license does gori use?

gori is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to gori?

The top alternatives to gori on Agent Skills Hub include Fray, h1-brain, agentseal. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools