
rails-activestorage-vips-audit
Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

A static analysis security vulnerability scanner for Ruby on Rails applications

Gradle plugin for Apache RAT that audits project files for missing license headers, generates HTML/XML reports, and fails builds on unapproved…

Technical rebuttal arguing for rejection of CVE-2025-56005 by demonstrating the proof-of-concept fails to execute and does not demonstrate arbitrary…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

A vulnerable version of Rails that follows the OWASP Top 10

Demonstrates that Claude Opus fails to identify CVE-2023-0266, hallucinating lock acquisitions and producing false positives, with reproducible demos…

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…