
pentest-mapper
A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

ArmourBird CSF - Container Security Framework


Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.


Discover input surfaces and security issues in compiled .NET assemblies — without running them.

TrustedRouter.com repo for secure LLM proxying

Unofficial api for cve.mitre.org

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Open source tooling to stop ICS phishing (malicious calendar invites)

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

PoC for CVE-2021-43557

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…