
React2Shell
Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.


Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

A reverse engineering framework written in Python.

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Trail of Bits Testing Handbook - appsec.guide

Security Scanner for Agent Skills

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

A coverage-guided fuzzer for pure Ruby code and Ruby C extensions

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.

A lightweight dynamic instrumentation library

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages
