
Log4ShellAuditor
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

Script to audit GitHub Action Workflow files for potential vulnerabilities.


Draw.io libraries for threat modeling diagrams

Go library for safe YAML and shell generation, using syntax-aware templates to detect and block injection attacks via annotations for trusted data.

jackson-databind 2026 年 11 条安全公告自查:扫源码注解降噪,告诉你真中几条;逐条求交集给出真正到位的版本(2.18.9/2.21.5/3.1.5,不是 advisory 上最常见的 2.21.4) CVE-2026-54515 / CVE-2026-54512


LLM powered fuzzing via OSS-Fuzz.


AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

GitHub Actions workflow sandbox for CVE-2025-55192 reproduction

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool