
iac-scan-runner
Service that scans your Infrastructure as Code for common vulnerabilities

Service that scans your Infrastructure as Code for common vulnerabilities

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

This skill helps Claude write secure code and prevent common vulnerabilities.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

The code for personally reproducing the corresponding vulnerability

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Real-time guardrails for Claude Code tool calls.

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

Exploit for CVE-2022-22947: remote code execution in Spring Cloud Gateway via crafted requests to the Actuator endpoint. Includes Python script and…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Capability-based WASM runtime for executing untrusted AI-generated code with enforced CPU, memory, time, I/O, and filesystem limits. Provides…

Exploit for CVE-2021-45232 targeting Apache APISIX Dashboard remote code execution vulnerability. Provides proof-of-concept for security testing and…

A PoC exploit for CVE-2020-13945 - Apache APISIX Remote Code Execution (RCE)

OAuth 2.0 client library for Kit applications supporting authorization code, PKCE, client credentials, and refresh token flows with built-in provider…

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…