
codeql
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Go static analysis tool that checks for security issues using an AST.

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.


The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.


Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

obride with CVE-2018-25075

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

This skill helps Claude write secure code and prevent common vulnerabilities.