
threat-modeling-mcp-server
MCP server for structured STRIDE-based threat modeling with automatic code validation, business context analysis, and comprehensive report generation…

MCP server for structured STRIDE-based threat modeling with automatic code validation, business context analysis, and comprehensive report generation…

Open-source secret scanner in Rust

OWASP Secure Agent Playbook Project

Hunt for AI coding artifacts containing secrets.

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

KQL Injection in adx-mcp-server via table_name parameter — CVSS 8.8

Scan codebases and GCP projects for exposed API credentials

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the…

Proof-of-concept exploit for CVE-2022-26884 targeting Apache DolphinScheduler, enabling remote code execution via crafted requests to the workflow…

Open-source, cross-platform, multi-purpose security auditing tool

Open source compliance tool for development platforms.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A wrapper around grep, to help you grep for things