
ephemera
Self-hosted SSH Certificate Authority replacing static keys with short-lived certificates, enforcing WebAuthn MFA, RBAC, and tamper-evident audit…

Self-hosted SSH Certificate Authority replacing static keys with short-lived certificates, enforcing WebAuthn MFA, RBAC, and tamper-evident audit…

Gradle plugin for Apache RAT that audits project files for missing license headers, generates HTML/XML reports, and fails builds on unapproved…

Scans Heroku applications for a critical Rails remote code execution vulnerability (CVE-2013-0333) and identifies unpatched instances requiring…

Chef cookbook that detects and fails runs on servers vulnerable to CVE-2014-3566 (POODLE) by scanning specified SSL ports, serving as both a security…

Inspect all of your heroku apps to see if they are running a vulnerable version of Rails

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…