
threatspec
threatspec - continuous threat modeling, through code

threatspec - continuous threat modeling, through code

Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀


Demonstrates command injection via unsanitized Git URLs in CI/CD pipelines, including a vulnerable build script and exploit example for a critical…

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during…

Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

Slides for Developing Secure Software in 2024 at CanSecWest

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

Test repo: simulates CVE-2025-30066 style compromised GitHub Action (for security research/testing chainradar)

Synthetic demo target for Endor Labs EXPOSURE, tracking CVE-2024-12886 with a deliberately vulnerable dependency and a one-click PR-based fix…

Synthetic demo target for CVE-2024-10821 vulnerability detection and automated fix via compensating control. Demonstrates one-click PR-based…

Detection of the React Server Actions Exploit vector – CVE-2025-55182 / CVE-2025-66478

npm repo with ejs CVE-2022-29078 (CVSS 9.8, EPSS 32%) for Dependabot automerge testing