Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for security teams, bug-bounty hunters, and red-team consultants who want a single operator console for running multi-step authorized pentests with a durable evidence plane instead of stitching ad-hoc shell sessions and findings together by hand.
Who should use it
Who should skip it
Hold off on yv1ing/Z3r0 for mission-critical workflows without a containment strategy, explicit approvals, and a hands-on security review.
About this signal
yv1ing/Z3r0 is tracked by RepoRadar as an agent project in the Radar section. First seen 2026-07-12; the source record was last checked on 2026-07-12. The current verdict is 'worth watch' with a Silver tier and advanced setup difficulty. Across RepoRadar's eight signals, yv1ing/Z3r0 is strongest on open-source/build quality (8.4) and workflow potential (7.6) and weakest on setup ease (4.2) — a profile worth weighing against your own priorities. This page summarizes the public evidence on the linked source page and states where additional review is still needed.
How this item is evaluated
The yv1ing/Z3r0 record combines a 6.8/10 composite score with separate popularity (5.3), risk (medium), and setup (advanced) signals. See the scoring methodology for the current weights and evidence definitions.
Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.
Risk explanation
It is a security workbench — deployment in regulated or multi-tenant environments requires the same human-in-the-loop controls as any offensive-security tooling; The default sandbox image bundles credential-testing and reverse-engineering tools that may require additional policy review before use.