
security-audit-skill
A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

A wrapper around grep, to help you grep for things

Automatic SSTI detection tool with interactive interface

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Fuzzing Framework for Modules in Apache HTTPD Server

Laravel debug mode - Remote Code Execution (RCE)