
rea
Reverse engineer anything with agents, from app behavior down to native binaries.

Reverse engineer anything with agents, from app behavior down to native binaries.

Go CLI that deobfuscates javascript-obfuscator (obfuscator.io) output and unminifies JavaScript using AST transforms, static decoding, and a goja…

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

Fix-Like Artifacts With Embedded Defects

Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and…

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Security Scanner for Agent Skills

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

Security review of CVE-2024-3094 (XZ Utils backdoor) including threat modeling, static/dynamic code analysis, fuzzing with AFL++, and a…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.


Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize