
awesome-ai-security
A collection of awesome resources related AI security

A collection of awesome resources related AI security


Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

GitHub Actions workflow sandbox for CVE-2026-45132 reproduction

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Portable security rules for the action boundary of AI agents

In-depth analysis of cve-2026-26555


IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

This is an incident response playbook we created for the Vercel April 2026 compromise


IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.