
skulto
Offline and security-first tool for syncing and managing agent skills

Offline and security-first tool for syncing and managing agent skills

Proof of concept for CVE-2024-24590

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Exploit for remote command execution in Golang go get command.

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Signing-key abuse and update exploitation framework

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

CocoaPods RCE Vulnerability CVE-2024-38366

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

Bash script to detect and remediate vulnerable xz-utils versions (5.6.0/5.6.1) by replacing them with a stable, uncompromised build from source.

Shell script to check if your system has a vulnerable version of XZ Utils affected by CVE-2024-3094, enabling quick detection of the supply-chain…

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.