
alibi
Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

On-prem API gateway for AI coding agents with per-engineer cost attribution, hard budgets, egress governance (secrets/entity scanning), context-rot…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

provides a Firewall Manager API designed to centralize and streamline the management of firewall configurations

This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

PHP 8.4+ security library (mirror)

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

SecureCivic is a citizen-built, open source identity verification platform designed for SSA adoption. It replaces private data brokers with a secure,…

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…