
ActBench
Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"


Apple Silicon device emulator.

Framework for compiling and executing Go applications on bare metal processors, enabling secure firmware development with reduced attack surface…

A fuzzer for full VM kernel/driver targets

Give coding agents a disposable Linux VM, not your laptop

Lightweight fuzzing of a memory snapshot using KVM

Rust library and format specification for creating and loading Independent Guest Virtual Machine (IGVM) files, supporting hardware-isolated VMs with…

RISC-V Virtual Machine

Go Trusted Execution Environment (TEE)

WASM sandbox with capability enforcement for AI agent code. Agents can only call explicitly provided tools with defined constraints. Sandboxed…

Lord Of Active Directory - automatic vulnerable active directory on AWS

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

Qubes containerization on Windows

Firecracker made simple. Spin up secure microVMs in milliseconds, from install to interactive shell in one command.

GoTEE - example application

Reference analysis of a Linux kernel Open vSwitch memory-corruption vulnerability, covering root cause, impact, detection commands, and mitigation…

Rust exploit PoC for Linux kernel LPE CVE-2026-31431 (AF_ALG page-cache write) plus eBPF runtime defense blocking AF_ALG socket creation via LSM or…