
wardn
credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

TrustedRouter.com repo for secure LLM proxying

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Better PHP rate limiting using Redis.

Corelight Sensor API command-line client

A small, auditable, terminating, deterministic micro-policy engine

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

An implementation of a vulnerable MCP server using mcp-go

SAML v2.0 bindings in Java using JAXB

Cryptographically signed delegation receipts for AI agents. Define exactly what an AI can and can't do — signed, verifiable, tamper-proof.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…