


The vibe-coding security sentinel. Apache-2.0 agentic security toolkit for AI-assisted projects: 5 deterministic scouts + LLM Brain Layer (BYOK…

Managing GitHub Advanced Security (GHAS) Controls at Scale

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

OWASP Security Culture repository

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Trivy example module for WordPress

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Step-by-step tutorial for detecting CVE-2024-3094 (XZ Backdoor) in container images using Trend Micro Vision One TMAS CLI, with automated scanning…

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.

An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046

CosmicSting (CVE-2024-34102) POC / Patch Validator

InSpec profile to verify a node is patched and compliant for CVE-2017-8543

Exploit for CVE-2022-25174 in Jenkins Pipeline Shared Libraries plugin, demonstrating code injection via crafted library definitions for security…

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.