
JAW
JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

Scanner di vulnerabilità web in Python: SQL injection, XSS , path traversal, security headers. Crawler, dashboard Flask, report in un PDF

OWASP Foundation Web Respository

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Main repo for hosting release binaries

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。

Mind-Maps of Several Things

A wrapper around grep, to help you grep for things