
mcp-stdio-shellguard
Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Static analyzer for Flutter/Dart AOT snapshots — recovers function names, class hierarchies, call graphs, and behavioral signals from libapp.so…

Build and query a graph database representation of source code

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

Educational reproduction of CVE-2026-14628 path traversal vulnerability with vulnerable and secure code examples, fix explanation, and runnable demos…

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…


Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash…

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

C# source-code obfuscator that replaces character and string literals with emojis and randomizes class, interface, method, and variable names using…

Reproduction and root cause analysis of CVE-2024-35333, a stack buffer overflow in html2xhtml 1.3, with ASan crash output and code-level mitigation…

simple application with a (unreachable!) CVE-2022-45688 vulnerability

Python source code auditing and static analysis on a large scale

Another RTTI Parsing IDA plugin

Scans compiled Java archives (JAR/WAR) for ECDSA algorithm usage to detect CVE-2022-21449 vulnerability. Recursively examines .class files with…

Generate Objective-C headers from Mach-O files.

Filesystem scanner for Log4Shell (CVE-2021-44228) and related CVEs. Detects vulnerable JAR files via hash matching and class presence. Runs…