
sast-scan-action
GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

Shell injection in Rebar3

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

GameLoop update MITM

Proof-of-concept code for Android APEX key reuse vulnerability

CVE-2025-65964 PoC - Malicious Git Hooks

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

CocoaPods RCE Vulnerability CVE-2024-38366

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Git-LFS RCE Test

Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

Proof-of-concept exploit for CVE-2024-5082, a remote code execution vulnerability in Sonatype Nexus Repository Manager 2 via crafted Maven artifacts…