
nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see…

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

OWASP Smart Contract Security (SCS) Project

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Documenting the internals of Fingerprint Pro's commercial agent, not the open-source FingerprintJS library

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A collection of my Semgrep rules to facilitate vulnerability research.

A pure Rust reimplementation of libxml2

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)


Application Security Verification Standard

Trail of Bits Testing Handbook - appsec.guide

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

Semantic inspector for SQL — catches fan-out double-counting, additivity violations, wrong join keys, and policy breaches before the query runs.…