
codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Bandit is a tool designed to find common security issues in Python code.

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

AST-based Python code transformation & deobfuscation framework


BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

a static analysis tool for finding vulnerabilities in C/C++ source code

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

C++ python bytecode disassembler and decompiler

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata