
security-audit-skill
A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings
Tools for dissecting, understanding, and reverse engineering malicious software behavior.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

A Linux version of the ProcDump Sysinternals tool

Proof of concept code for Datadog Security Labs referenced exploits.

Read-only scanner for what lets a repository run code in a coding agent (Claude Code, Codex, Cursor, Copilot): git settings, hooks, and committed MCP…

Reverse-engineered Logi Options+ agent IPC protocol. Switch Logitech multi-host devices programmatically via Unix socket (macOS) or named pipe…

The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more

A library for creating, reading and editing PE files and .NET modules.

ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866)

amavis is a high-performance email content filter framework written in Perl.

Reverse engineering analysis of StealC Stealer, an info-stealer that uses RuntimeBroker.exe hollowing, C2 infrastructure, and payload extraction.…

Dependency-free Python CLI to unpack, inspect, edit, and rebuild iOS .ipa archives, converting plists and strings to XML while preserving Mach-O…

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Hands-on challenges for learning how to reverse engineer Flutter applications.

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…

Kubernetes RBAC static analysis & visualisation tool

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Creation of multiple Malware tools consisting of evasion, enumeration and exploitation

Python Command-Line Ghidra MCP