
lightweight_static_analysis
Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Static code audit of CVE-2024-57521, an authenticated SQL injection in RuoYi-Vue's generator module, with source-to-sink analysis and a %0b filter…

CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

Easy setup of static analysis tools for Android and Java projects.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

This skill helps Claude write secure code and prevent common vulnerabilities.

A security scanner for your LLM agentic workflows

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Curated Ghidra scripts to automate reverse engineering and vulnerability analysis: locate insecure functions, extract decompiler pseudocode, fix…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…