
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

MCP server for Slither static analysis of Solidity smart contracts

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Executable security regression testing for agentic applications and MCP-integrated systems.

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

一个由AI生成的漏洞验证应用

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

A contextual security auditing system for research artifacts

The code for personally reproducing the corresponding vulnerability