
semgrep-rules
A collection of my Semgrep rules to facilitate vulnerability research.

A collection of my Semgrep rules to facilitate vulnerability research.

This skill helps Claude write secure code and prevent common vulnerabilities.

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

a static analysis tool for finding vulnerabilities in C/C++ source code

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

RIPS - A static source code analyser for vulnerabilities in PHP scripts

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

find hardcoded strings from source code

Static code analysis tool based on Elasticsearch

Batch-decompile binaries with Ghidra from the command line, generating per-function C files, callgraphs, BSim signatures, and optional SAST results…


Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU