
libwebp-checker
A tool for finding vulnerable libwebp(CVE-2023-4863)

A tool for finding vulnerable libwebp(CVE-2023-4863)

Vulnerability Scanner for Detecting Publicly Disclosed Vulnerabilities in Application Dependencies

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Portable security rules for the action boundary of AI agents

Aggregates vulnerability data from multiple databases into CycloneDX SBOMs, generating deduplicated VEX, HTML, and GitLab-compatible reports for…

[EXPERIMENTAL] Kubernetes Operator for Image Assurance

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094

Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

On-prem API gateway for AI coding agents with per-engineer cost attribution, hard budgets, egress governance (secrets/entity scanning), context-rot…

A Public Package Scanner for The Community

The credit score for npm packages. Analyze package reputation, maintenance, security, publisher trust, and ecosystem health before you install any…

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…