Below you will find pages that utilize the taxonomy term “Htunn”
August 29, 2026
offsec-ai Security Scanner
Version updated for https://github.com/Htunn/offsec-ai to version v2.7.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary offsec-ai is an offensive-security toolkit that combines classic network reconnaissance with modern AI/LLM security testing. It automates tasks such as scanning live AI/LLM endpoints, probing Model Context Protocol (MCP) servers, and performing full-stack infrastructure security assessments. The tool can also detect and report on secrets in responses from Postman collections.
August 28, 2026
offsec-ai Security Scanner
Version updated for https://github.com/Htunn/offsec-ai to version v2.7.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary offsec-ai is an AI/ML-driven security toolkit that combines classic network reconnaissance with modern security testing. It performs full-stack infrastructure security assessments, actively attacks Model Context Protocol (MCP) servers for known CVEs, and integrates with Postman collections for comprehensive API vulnerability scanning and exploitation. The tool is designed to help authorized red teams identify and mitigate vulnerabilities in systems using LLM endpoints.
August 27, 2026
offsec-ai Security Scanner
Version updated for https://github.com/Htunn/offsec-ai to version v2.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README automates the testing of AI/LLM endpoints and infrastructure using the offsec-ai toolkit. It focuses on security testing, specifically identifying vulnerabilities like missing authentication, unresolved variables, and secrets, as well as actively attacking known CVEs using the Model Context Protocol (MCP). The action is designed for authorized red-team engagements and requires explicit permission to use against systems it does not own or have permission to test.