
EscalateGPT
An AI-powered tool for discovering privilege escalation opportunities in AWS IAM configurations.

An AI-powered tool for discovering privilege escalation opportunities in AWS IAM configurations.

A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Red portatil de reconocimiento inteligente con IA offline

Active Directory LDAP Security Auditor with AI-Powered Analysis - By Ayi NEDJIMI https://ayinedjimi-consultants.fr

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

A productionized greedy coordinate gradient (GCG) attack tool for large language models (LLMs)

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

Detailed disclosure of CVE-2025-67511, a command injection vulnerability in the CAI framework's SSH tool that allows AI agents to be tricked into…

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange…

Bypass llm guardrails by confusing it with fabricated tool output.

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

Technical Details and Exploit for CVE-2024-11394

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.