
JavaSecLab
Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Twitter vulnerable snippets

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

一个由AI生成的漏洞验证应用

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)


Executable security regression testing for agentic applications and MCP-integrated systems.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Application Security Verification Standard

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
