
nono
safe execution paths for agents - zero trust, zero setup, zero latency.

safe execution paths for agents - zero trust, zero setup, zero latency.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…


Proof of concept of CVE-2017-1000117

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of…

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

Demo consumer for invokeai 5.0.1 (CVE-2024-10821; version named in CVE prose) — endorctl scan target

Demo consumer for ollama v0.5.0 (vulnerable range for CVE-2024-12886) — endorctl scan target

general purpose workaround for the log4j CVE-2021-44228 vulnerability

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Seal Security example — vulnerable pip app (PyYAML CVE-2020-14343) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)