
litellm-command-injection-security-assessment
Professional vulnerability assessment report for LiteLLM command injection risk, including executive summary, technical impact, remediation, and…

Professional vulnerability assessment report for LiteLLM command injection risk, including executive summary, technical impact, remediation, and…

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

Pre-auth RCE scanner for Langflow < 1.8.0 — Route Injection + Vertex Injection → Code Execution (CVSS 9.8)

A tool which can be used to generate password list or dictionary from the details of the target

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

Fingerprint OpenAI-compatible LLMs from tokenizer and behavior signals.

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

Security analysis tool identifying risks in Blackbox.ai extensions, including credential harvesting, unpatched CVEs, and privacy threats from hidden…

AI-Powered Active Directory Attack Path Analysis with BloodHound - By Ayi NEDJIMI https://ayinedjimi-consultants.fr

My manifesto, and stories, images, and phun stuff

AI-native penetration testing IDE where operators and an AI agent share browser, terminals, traffic capture, shells, asset graph, tasks, and evidence…

Red team framework and multi-operator C2 platform with AI agents, malleable implants, rootkits, phishing engine, and 741 CLI commands covering the…

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…