
call_map
Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Go static analysis tool that checks for security issues using an AST.

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool


Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

CLI tool to scan codebases for quantum-vulnerable cryptography

CVE-2026-39259

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

解决网络安全漏洞

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

A CodeQL query to find CVE 2022-35737

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)