
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

A Feature Rich Modular Malware Configuration Extraction Utility for MalDuck

Trivy example module for WordPress

Tools for analyzing and reverse engineering MediaTek baseband firmware, including file extraction, symbol parsing, and Ghidra integration for modem…

Evidence-driven C/C++ vulnerability remediation pipeline + http-parser case study (CVE-2024-22019-class). Python core, React 19 console, 17-test…

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

Workshop on firmware reverse engineering

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive analysis end…

FARO - Document Sensitivity Detector

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Zero shot vulnerability discovery using LLMs

ecurity patch for CVE-2023-26136 in tough-cookie 2.5.0 - Prototype pollution vulnerability fix with backward compatibility