
enforcement-coverage
Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Vulnerability Assessment Scanner with Report Generation

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

CVE-2026-39259

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Sourcetrail - free and open-source interactive source explorer

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

grep rough audit - source code auditing tool

This skill helps Claude write secure code and prevent common vulnerabilities.

A static code analysis for WordPress (and PHP)