
GuardModel
GitHub Action that scans ML model files for malicious code and security vulnerabilities

GitHub Action that scans ML model files for malicious code and security vulnerabilities

Poor (rich?) man's bug bounty pipeline https://dubell.io

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

GitHub Actions Pipeline Enumeration and Attack Tool

Identify hardcoded secrets in static structured text

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.