No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by hahwul · MCP Server · ★ 102
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is gori safe to install? View the security audit →
Hack from the terminal. Installation • Usage • Documentation • Contributing gori (고리 — Korean for ring, link, loop) sits in the loop between your client and its target, capturing every request and response as a flow you can replay, fuzz, and scan across HTTP/1.1, HTTP/2, WebSocket, gRPC, and SSE, and intercept in flight on HTTP/1.1 and HTTP/2. Core assessment actions that cross surfaces use the same engines, and those workflows are also available through and MCP, so scripts and AI agents can drive the same engagement. The capability matrix names the protocol and surface limits explicitly. ![gori TUI — the History tab listing captured HTTP flows]
| Stars | 102 |
| Forks | 14 |
| Language | Crystal |
| Category | MCP Server |
| License | Apache-2.0 |
| Quality Score | 72.7851289189607/100 |
| Open Issues | 13 |
| Last Updated | 2026-09-21 |
| Created | 2026-06-13 |
| Platforms | cli, mcp |
| Est. Tokens | ~17k |
These tools work well together with gori for enhanced workflows:
Looking for a gori alternative? If you're comparing gori with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
AI-native security toolkit — fray go target.com scans everything. 7,800+ payloads, 98 WAF vendors, 42+ recon c
MCP server that connects AI assistants to HackerOne for bug bounty hunting
Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply cha
MCP server enabling agents to debug HTTP requests better (using powhttp)
AI-powered penetration testing MCP server
TUI / CLI config manager for agentic harnesses (Amp, Claude Code, Opencode, Goose, Copilot CLI, Crush, Droid)
Explore other popular mcp server tools:
gori is A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.. It is categorized as a MCP Server with 102 GitHub stars.
gori is primarily written in Crystal. It covers topics such as bugbounty, cli, crystal.
You can find installation instructions and usage details in the gori GitHub repository at github.com/hahwul/gori. The project has 102 stars and 14 forks, indicating an active community.
gori is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to gori on Agent Skills Hub include Fray, h1-brain, agentseal. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: