
cryptoptic
CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

Apache RAT (Release Audit Tool) Gradle Plugin

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

CVE-2026-42533 Nginx

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively

log4j vulnerability wrapper scanner for CVE-2021-44228

I have created AegisJava, a tool to fix (detect and mitigate) CVE-2025-30749.

cve-2025-4615 poc & deep dive

This is an OpenSSL Vulnerability Detection Script for CVE-2022-2274

Anteater - CI/CD Gate Check Framework

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Ruby-based exploit for CVE-2020-15169, demonstrating a specific web application vulnerability with proof-of-concept code for security testing and…

.NET/PowerShell/VBA Offensive Security Obfuscator

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings