
toolbox
Collaborative application security testing between humans and agents via CLI and MCP

Collaborative application security testing between humans and agents via CLI and MCP

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

CyberArk Security Audit

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Exploit for CVE-2021-30180 targeting Apache Dubbo RPC framework, enabling remote code execution via crafted RPC requests in vulnerable versions.

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Http request smuggling vulnerability scanner

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

An intentionally designed broken web application based on REST API.