
JShunter
jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

This skill helps Claude write secure code and prevent common vulnerabilities.

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Proof-of-concept and static analysis toolkit for finding speculative race condition (SCUAF) gadgets in Linux kernel. Includes 1200+ gadget dataset.

Python Command-Line Ghidra Decompiler

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Go static analysis tool that checks for security issues using an AST.


Checklist and tools for increasing security of Apache Airflow

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Clickbait. The CVE is AI slop.

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata