
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Reproducer that exploits credential vending before location validation in Apache Polaris Iceberg REST, proving cross-tenant cloud reads and bucket…

An implementation of a vulnerable MCP server using mcp-go

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Kubernetes policy engine with OPA-based admission control, mutation, and audit for enforcing security and compliance configurations.

The easiest, and most secure way to access and protect all of your infrastructure.

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Honeypot, Automated Deception Framework.
