
codeql
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.


Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

a static analysis tool for finding vulnerabilities in C/C++ source code

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

This skill helps Claude write secure code and prevent common vulnerabilities.

grep rough audit - source code auditing tool

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting


PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…