
pigeon
Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

TrustedRouter.com repo for secure LLM proxying

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Better PHP rate limiting using Redis.

Corelight Sensor API command-line client

A small, auditable, terminating, deterministic micro-policy engine

An implementation of a vulnerable MCP server using mcp-go

SAML v2.0 bindings in Java using JAXB

Cryptographically signed delegation receipts for AI agents. Define exactly what an AI can and can't do — signed, verifiable, tamper-proof.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

mcp-remote exposed to OS command injection

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

PlaceOS authentication service and API gatekeeper.

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

Zero-knowledge privacy platform for confidential API key management, encrypted vault, and secure chat. Built on Oasis Sapphire TEEs

PHP 8.4+ security library (mirror)