
sec-af
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

OWASP Autonomous Penetration Testing Standard

Signing-key abuse and update exploitation framework

Proof-of-concept code for Android APEX key reuse vulnerability

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Exploit for CVE-2024-0402 in Gitlab

Repository for CVE-2014-4936 POC code.

CocoaPods RCE Vulnerability CVE-2024-38366

Git-LFS RCE Test

Shell injection in Rebar3


GameLoop update MITM

Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

Sonatype Nexus 2 - Authorized RCE POC