
skulto
Offline and security-first tool for syncing and managing agent skills

Offline and security-first tool for syncing and managing agent skills

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Proof-of-concept for CVE-2026-23001: demonstrates RCE through unsafe pickle deserialization in Hugging Face Transformers by crafting a malicious…

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Generate malicious files using recently published bidi-attack (CVE-2021-42574)

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

CVE-2025-65964 PoC - Malicious Git Hooks

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

CVE-2025-53547 one of poc code

Bash script to detect and remediate vulnerable xz-utils versions (5.6.0/5.6.1) by replacing them with a stable, uncompromised build from source.

Script to handle CVE 2022-42889

CocoaPods RCE Vulnerability CVE-2024-38366

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…