


Notes about attacking Jenkins servers

veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

A tool to scan Kubernetes cluster for risky permissions

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

a guard that blocks catastrophic agent actions

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…


A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Model Context Protocol server for autonomous vulnerability discovery


Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

GitHub Actions Pipeline Enumeration and Attack Tool

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…