
roninforge-hono
Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Educational lab demonstrating CVE-2020-11023 jQuery XSS vulnerability with attack payloads, mitigation techniques (text(), CSP, input validation),…

Java utility library with patched CVE-2022-4244 vulnerability, providing common helper classes for I/O, reflection, and CLI argument parsing in…

Type-safe Java Mustache templating engine with compile-time template validation, static value binding, and extensible escaping for HTML and other…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

OSWE, OSEP, OSED, OSEE

Clickbait. The CVE is AI slop.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Python Command-Line Ghidra Decompiler

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

A Bitbucket Pipe to trigger SonarCloud analysis

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…