
agentsh
Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

DSC resources to simplify administration of certificates on a Windows Server.

Secure agents in seconds with permissions enforced at runtime.

This repository discloses a server-side authorization bypass in Instagram, which allowed unauthenticated access to private timelines; it seems likely…

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

Simple Secure Keeper for Secrets

A terminal based tool for managing secrets with both tui and cli support

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

A modern git based age-encrypted secrets manager for teams.