
sh4d0wup
Signing-key abuse and update exploitation framework

Signing-key abuse and update exploitation framework

CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

OWASP Autonomous Penetration Testing Standard

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Proof-of-concept code for Android APEX key reuse vulnerability

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

Repository for CVE-2014-4936 POC code.

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Proof-of-concept exploit for CVE-2025-69599, demonstrating uncontrolled search path element in RayVentory Scan Engine's rvia and ndtrack binaries,…

Proof-of-concept exploit for CVE-2024-5082, a remote code execution vulnerability in Sonatype Nexus Repository Manager 2 via crafted Maven artifacts…

CocoaPods RCE Vulnerability CVE-2024-38366

CVE-2025-65964 PoC - Malicious Git Hooks