
keyhacks
Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Portable security rules for the action boundary of AI agents

Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

A GitHub recon/monitoring tool for finding internal leaks belonging to your organisation.

Poor (rich?) man's bug bounty pipeline https://dubell.io

A collection of tools to perform searches on GitHub.

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.