github TypeScript analyzed 1881712

opena2a-org/hackmyagent

github

Metasploit for AI agents: scan, attack, and fix AI agents and MCP servers. Open source security toolkit.

maintainer
opena2a-org
licence
Apache-2.0
first seen
2026-06-05
last seen
2026-09-11
releases · 30d
1
short id

opena2a-org/hackmyagent is an MCP server distributed on github, maintained by opena2a-org, tracked here since June 2026. It has shipped 86 releases and exposes 3 tools. Tools include hackmyagent_benchmark, hackmyagent_deep_scan, hackmyagent_scan. Its composite risk grade is E — an inferred review prompt computed from observed signals, not a verdict. 2 known CVEs on file.

what we found

2 advisories published against this server still applies to the version it ships, the most severe rated critical, most recently 2026-08-09.

Reading the source raised one review prompt — dangerous code — each a pattern worth a human look rather than a finding of fault.

Its 3 tools appear to reach filesystem, shell / exec, network and secrets, inferred from tool names, descriptions and input schemas rather than from observed behaviour.

full security breakdown →
tools 3
  • hackmyagent_benchmark
  • hackmyagent_deep_scan
  • hackmyagent_scan
release cadence · 90d 13 releases
06-15 00:00 07-29 00:00 now
recent releases last 10
version date src
v0.32.0 2026-08-20 github
v0.31.0 2026-08-11 github
v0.30.0 2026-08-11 github
v0.29.0 2026-08-09 github
v0.28.0 2026-08-09 github
v0.27.0 2026-08-08 github
v0.26.1 2026-08-07 github
v0.26.0 2026-08-06 github
v0.25.2 2026-08-05 github
v0.25.1 2026-07-28 github

view all →