
mcp-shark
Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

Run untrusted AI code safely, fast

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Chaos Monkey but for Audio Video Testing (webRTC and UDP)

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

Exploit for CVE-2023-51770 targeting Apache DolphinScheduler versions 3.2.1 and earlier, enabling remote code execution via crafted workflow…

Exploit for CVE-2023-51770 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in data source configuration.

Jakarta EE and MicroProfile application server runtime for development and containerized deployments, supporting cloud-native middleware with…

GitHub Actions Pipeline Enumeration and Attack Tool

Open Cloud Security Posture Management Engine

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network…

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Benchmark for evaluating AI agents on real-world tasks including vulnerability resolution, code debugging, and protein assembly in containerized…

Documenting your Threat Models with HCL

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…