
ai-ctf
Local AI Capture-the-Flag platform with guided lessons on prompt injection, tool-call abuse, and OSINT against six simulated chatbot personas.

Local AI Capture-the-Flag platform with guided lessons on prompt injection, tool-call abuse, and OSINT against six simulated chatbot personas.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Collection's of Tech Talk that are presented by me :)

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Collect VEX documents and update VEX Hub

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

CVE-2024-38526 - Polyfill Scanner

CVE-2022-46463 harbor公开镜像全自动下载脚本

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

Find log4j for CVE-2021-44228 on some places * Log4Shell

Curated collection of resources and analysis documenting the CVE-2024-3094 supply-chain backdoor in XZ Utils, including security advisories,…