
appsec-agent
A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

High-performance SMT solver for automated theorem proving, constraint solving, and program verification. Supports multiple theories and language…

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

OWASP Smart Contract Security (SCS) Project

OWASP Certified Secure-Software Developer

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Quickly find differences and similarities in disassembled code

Project Wycheproof tests crypto libraries against known attacks.

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。

Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…


Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack

PoC: identify silent security patches before CVE

Automated static analysis tools for binary programs

Checker for Lifetimes and other Refinement types