
API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API

Checklist of the most important security countermeasures when designing, testing, and releasing your API

The easiest, and most secure way to access and protect all of your infrastructure.

A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord,…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Your gateway to OWASP. Discover, engage, and help shape the future!

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

Knocker, a knock based access control service for your homelab

Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Service that scans your Infrastructure as Code for common vulnerabilities

On-prem API gateway for AI coding agents with per-engineer cost attribution, hard budgets, egress governance (secrets/entity scanning), context-rot…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

This script audits ServiceNow AI Agents for vulnerabilities like CVE-2025-12420, governance gaps, and compliance risks. Powered by CYBERDUDEBIVASH –…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…