

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Vulnerability Scanner for Detecting Publicly Disclosed Vulnerabilities in Application Dependencies

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

CVE-2026-43813: CloudAttestation enforceEnvironment bypass

Exploit for CVE-2024-0402 in Gitlab

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

RCE in NPM VSCode Extension

一个验证对CVE-2023-51385

Collect VEX documents and update VEX Hub

A Public Package Scanner for The Community

Public testing data. Samples of log4j library versions to help log4j scanners / detectors improve their accuracy for detecting CVE-2021-45046 and…

793 confusable pairs missing from Unicode TR39, world-first cross-script dataset, font-aware SSIM scoring across 230 fonts and 22,000+ characters