No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by samugit83 · MCP Server · ★ 2.9k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is redamon safe to install? View the security audit →
Unmask the hidden before the world does An autonomous AI framework that chains reconnaissance, exploitation, and post-exploitation into a single pipeline, then goes further by triaging every finding, implementing code fixes, and opening pull requests on your repository. From first packet to merged patch, with human oversight at every critical step. <img height="34" src="https://img.shields.io/bad
| Stars | 2,901 |
| Forks | 592 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 61.3951491840017/100 |
| Open Issues | 16 |
| Last Updated | 2026-10-02 |
| Created | 2025-12-29 |
| Platforms | claude-code, mcp, python |
| Est. Tokens | ~25k |
These tools work well together with redamon for enhanced workflows:
Looking for a redamon alternative? If you're comparing redamon with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,
Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized pene
Model-agnostic plug-n-play LangChain/LangGraph agents powered entirely by MCP tools over HTTP/SSE.
一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。
A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Sca
Explore other popular mcp server tools:
redamon is Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and opens PRs that fix what it. It is categorized as a MCP Server with 2.9k GitHub stars.
redamon is primarily written in Python. It covers topics such as agentic-ai, ai, ai-pentesting.
You can find installation instructions and usage details in the redamon GitHub repository at github.com/samugit83/redamon. The project has 2.9k stars and 592 forks, indicating an active community.
redamon is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to redamon on Agent Skills Hub include CyberStrike, pentest-ai, pentest-ai-agents. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: