
agent-vault
A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Metlo is an open-source API security platform.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

This skill helps Claude write secure code and prevent common vulnerabilities.

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

layerleak the Docker Hub Secret Scanner

A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

mcp-remote exposed to OS command injection