
numasec
AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

Static code analysis plugin for Android project. (Checkstyle, PMD)

Skillscript — a small declarative language for authoring agent workflows. Runtime, compiler, and CLI.

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Accompanying PowerShell Modules for DevSec Defense Presentation

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)

🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix…

Demonstrates command injection via unsanitized Git URLs in CI/CD pipelines, including a vulnerable build script and exploit example for a critical…

Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamı

Test repo: simulates CVE-2025-30066 style compromised GitHub Action (for security research/testing chainradar)

Synthetic demo target for EXPOSURE — CVE-2018-21268 (traceroute) + CVE-2018-3757 (pdf-image)

Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

Synthetic demo target for Endor Labs EXPOSURE, tracking CVE-2024-12886 with a deliberately vulnerable dependency and a one-click PR-based fix…