
crapsecrets
A library for detecting known secrets across many web frameworks

A library for detecting known secrets across many web frameworks

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

AI-powered bug bounty hunting toolkit that works with or without subscription.

A wrapper around grep, to help you grep for things

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

A static + runtime security scanner for MCP (Model Context Protocol) servers

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

This Repositories contains list of One Liners with Descriptions and Installation requirements

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

A collection oneliner scripts for bug bounty

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Notes about attacking Jenkins servers

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

Checks Djangos /static/staticfiles.json for exposed creds using nuclei

Burp Plugin for Secret Matching