
appsec-agent
A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Application Security Verification Standard

OWASP Secure Agent Playbook Project


Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

The dependency-check repository has moved:

一个由AI生成的漏洞验证应用

Executable security regression testing for agentic applications and MCP-integrated systems.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

A vulnerable version of Rails that follows the OWASP Top 10

The Secure Coding Practices Quick-reference Guide from OWASP