
awesome-ai-security
A collection of awesome resources related AI security

A collection of awesome resources related AI security


Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

GitHub Actions workflow sandbox for CVE-2026-45132 reproduction

Portable security rules for the action boundary of AI agents


IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

This is an incident response playbook we created for the Vercel April 2026 compromise


A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

La siguiente regla YARA ayuda a detectar la presencia del backdoor en la librería liblzma comprometida en sistemas que utilizan las versiones 5.6.0 y…

CVE-2024-3094 XZ Backdoor Detector

Scanners for Jar files that may be vulnerable to CVE-2021-44228