
brakeman
A static analysis security vulnerability scanner for Ruby on Rails applications

A static analysis security vulnerability scanner for Ruby on Rails applications

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

A vulnerable version of Rails that follows the OWASP Top 10

Technical rebuttal arguing for rejection of CVE-2025-56005 by demonstrating the proof-of-concept fails to execute and does not demonstrate arbitrary…

Gradle plugin for Apache RAT that audits project files for missing license headers, generates HTML/XML reports, and fails builds on unapproved…

Demonstrates that Claude Opus fails to identify CVE-2023-0266, hallucinating lock acquisitions and producing false positives, with reproducible demos…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…