
agent-vault
A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

Authentication, authorization, traceability and auditability for SSH accesses.

CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

A tool to scan Kubernetes cluster for risky permissions

Review Access - kubectl plugin to show an access matrix for k8s server resources

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

Simple Secure Keeper for Secrets

A terminal based tool for managing secrets with both tui and cli support

cve cve-2026-60206 weblogic saml exploit poc vulnerability oracle scanner security

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.