
jsluice
Extract URLs, paths, secrets, and other interesting bits from JavaScript

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

A tool to hunt for credentials in github wild AKA git*hunt

AI-powered assistant for penetration testers that generates payloads, analyzes code, performs reconnaissance, and executes command-line actions to…

Shell scripts to clone and mirror Git repositories, compute deltas, and run gitleaks to detect secrets hidden in deleted or reset commits.

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

🧬 Extract and analyze contributors info from git repos

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

NCC Code Navigator

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…