
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A security scanner for your LLM agentic workflows

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

UT based automated fuzz driver generation

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

This skill helps Claude write secure code and prevent common vulnerabilities.

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.