
fickling
A Python pickling decompiler and static analyzer

A Python pickling decompiler and static analyzer

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Automated security analysis pipeline that runs CodeQL queries on GitHub repositories and uses LLMs to classify and filter true vulnerabilities from…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

A static + runtime security scanner for MCP (Model Context Protocol) servers

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Protection against Model Serialization Attacks

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

A benchmark for evaluating AI agents on fixing real-world security vulnerabilities.

Security Scanner for Agent Skills

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…