
static-file-checker
Checks Djangos /static/staticfiles.json for exposed creds using nuclei

Checks Djangos /static/staticfiles.json for exposed creds using nuclei

Anticipator is an open-source threat detection platform for multi-agent AI systems.

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

Parse and visualize /proc/self/environ on compromised Linux boxes — categorizes env vars by tech stack (AWS, Django, Rails, NodeJS, MySQL, K8s,…

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

automated web assets enumeration & scanning [DEPRECATED]

Anteater - CI/CD Gate Check Framework

AI coding agents that can't exfiltrate secrets or merge their own PRs.

The dependency-check repository has moved:

GitHub Actions Pipeline Enumeration and Attack Tool

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

Web-based dashboard to visualize, filter, and analyze secrets discovered by TruffleHog, with batch verification, export, and session management for…

Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

Infisical is the open-source platform for secrets, certificates, and privileged access management.

OSINT reconnaissance tool for network discovery, subdomain enumeration, IP enrichment, and secret detection via certificate logs, Shodan, and GitHub…

「🔑」A tool used to hunt down API key leaks in JS files and pages