
smokedmeat
A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Staged static taint analysis framework for GitHub Actions workflows. Detects code injection vulnerabilities using taint-tracking and an impact…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Multi-layer security framework for AI agent ecosystems. Provides pre-installation skill auditing, file integrity monitoring, runtime protection, and…

Software Component Verification Standard (SCVS)

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

Supply-chain Levels for Software Artifacts

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

A software supply chain framework powered by Nix.

Python reference implementation of The Update Framework (TUF)

Signing-key abuse and update exploitation framework

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…