
mcp-xray
Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

A proof of concept for the git vulnerability CVE-2024-32002

It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only…

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Portable security rules for the action boundary of AI agents

Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Apache RAT (Release Audit Tool) Gradle Plugin

integration examples for the CVE-2020-25860 fix

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.