
check-spelling
Spelling checker action to check spelling in repositories / pull requests / commits

Spelling checker action to check spelling in repositories / pull requests / commits

threatspec - continuous threat modeling, through code


Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Staged static taint analysis framework for GitHub Actions workflows. Detects code injection vulnerabilities using taint-tracking and an impact…

Skillscript — a small declarative language for authoring agent workflows. Runtime, compiler, and CLI.

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Accompanying PowerShell Modules for DevSec Defense Presentation

Centralized DevSecOps platform for vulnerability management, CI/CD security integration, automated security assessment aggregation, and fostering…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Defense Against the Shai-Hulud Supply Chain Attack

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…