
sast-scan-action
GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Twitter vulnerable snippets

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

一个由AI生成的漏洞验证应用

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)


Executable security regression testing for agentic applications and MCP-integrated systems.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Application Security Verification Standard

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.


AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)