
security-harness
Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Go proof-of-concept demonstrating CVE-2026-46595 in golang.org/x/crypto/ssh, using symbol inspection of stripped binaries and image scans to verify…

REx@Skill - Agentic Reverse Engineering eXecution Skill for binary vulnerability discovery

Web vulnerability scanner built with C++17 and Qt 6, featuring a GUI, CLI, configurable crawling, and JSON reports. Reconstructed for educational…

Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in…

Insecure Temp File Reuse in extract_zipped_paths()

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075

Evidence-driven Linux kernel vulnerability research harness used in the investigation of CVE-2026-31720

Agentic Framework for Synthesizing CodeQL Queries

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

A scanner and testter of the CVE-2025-11001 of 7-zip

Demonstrates a path traversal vulnerability in an official eml-parser example script, allowing arbitrary file write via crafted attachment filenames,…

Scans Angular projects for XSS vulnerabilities in SVG elements and unsafe bindings, generating a vulnerability report with line numbers and…

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Detailed analysis of CVE-2021-22569, a high-severity denial-of-service vulnerability in protobuf-java, including affected versions, patched versions,…

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

Defensive vulnerability-research project comparing vulnerable and patched Grandstream GXP1600 firmware for CVE-2026-2329, using SquashFS extraction,…