
SkeletonKey
CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox
Code Implementation of "Pattern Enhanced Multi-Turn Jailbreaking: Exploiting Structural Vulnerabilities in Large Language Models"

Black-box attack framework that hijacks reasoning in agentic retrieval-augmented generation systems by injecting poisoned documents, with support for…

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

Intentionally vulnerable machine learning model for hands-on security training. Explore common ML vulnerabilities, adversarial attacks, and defensive…

Self-referenced local contrast for knowledge-poison detection in retrieval-augmented generation

Research implementation of Hop-Decayed Influence (HDI) and the 3S attack framework, exposing structural auxiliary indexing vulnerabilities in…

Privaxy is the next generation tracker and advertisement blocker. It blocks ads and trackers by MITMing HTTP(s) traffic. Also check out my new…

HookChain: A new perspective for Bypassing EDR Solutions

Compares Windows archiver support for Mark of the Web propagation, helping teams assess which tools preserve MOTW and mitigate macro-based malware…

Attempt at Obfuscated version of SharpCollection

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Covert data exfiltration via DNS

Benchmarking prompt injection detections for web agents.

PoC MSI payload based on ASEC/AhnLab's blog post

The code for ACM MM2024 (Multimodal Unlearnable Examples: Protecting Data against Multimodal Contrastive Learning)

Research code reproducing multi-turn LLM jailbreak experiments (FITD, MRCJ, ActorAttack, X-Teaming) from the SoK intent-oriented systematization…

Proof-of-concept exploit for CVE-2026-73292: CSRF attack on Semaphore UI password change endpoint, serving a malicious page that silently resets an…