
duo-agentflow-auditor
AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

A vulnerable version of Rails that follows the OWASP Top 10

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

Android security insights in full spectrum.

Symbolic verification tool for security protocols using multiset rewriting and constraint solving to prove secrecy, authentication, and equivalence…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Security-focused static analysis for the Phoenix Framework