
agentZ
Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.

BPF LSM blocker for CVE-2026-31431 (Copy Fail) - zero-reboot remediation for OpenShift 4

Proof-of-concept demonstrating a Node.js permission model bypass (CVE-2026-21636) that allows network access via undici/fetch to local services,…

Seccomp-based mitigation for CVE-2026-31431, a Linux kernel LPE. Blocks AF_ALG socket via PAM module and standalone wrapper, with auto-detection of…


Here comes the paintrain!

Qubes containerization on Windows

Securekit is a protocol-agnostic security kernel that enforces zero-trust, sandboxed execution for AI tool use. It sits between any LLM or agent…

Cross Distribution Exploit Testing

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

kali-linux-docker

Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Run Windows inside a Docker container with KVM acceleration, automatic installation, and customizable resources. Supports multiple Windows versions,…

Linux application sandboxing and distribution framework

Run Firefox in a rootless Podman container with dropped capabilities, isolated networking, and ephemeral storage to contain sandbox escapes and…

Lightweight, secure Linux sandboxes for untrusted processes. Runs in the browser and on the server.

Microsoft's curated repository of secure boot objects (KeK, Db, Dbx) for firmware and runtime, enabling transparent revocation updates and…