
needle
The iOS Security Testing Framework

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

The Secure Coding Framework

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Vulnerability Assessment Scanner with Report Generation

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered bug bounty hunting toolkit that works with or without subscription.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

This skill helps Claude write secure code and prevent common vulnerabilities.

A list of awesome penetration testing tools and resources.

PHP Static Analysis Tool - discover bugs in your code without running it!

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.