
CVE-2026-29000
Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

The leading native Python SSHv2 protocol library.

Native C++ access to Active Directory over ADWS, no .NET, no WCF, no HTTP stack.

A modern git based age-encrypted secrets manager for teams.

A command-line interface tool for managing Azure Privileged Identity Management (PIM) role activations directly from your terminal.

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

The Symfony PHP framework

Secure, private AI agent operating system with local encrypted storage, OAuth/SSO authentication, policy-based access control, and extensible…

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Node.js SDK for capturing and replaying API calls made to/from your service

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Better PHP rate limiting using Redis.

🔐 Lightweight CLI utility designed to synchronize SSH public keys from remote URLs into local authorized_keys files

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…