
wp2shell-PoC
CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

Transparent file encryption in git

The next generation encrypted file sharing project

Automated exploit for CVE-2026-27944 in Nginx UI: downloads and decrypts backups, extracts secrets, and creates rogue admin accounts for full…

Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to…

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

FOGProject Authentication bypass CVE-2025-58443 Exploit