
ship-safe
The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Proof-of-concept code for Android APEX key reuse vulnerability

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.