
gitxray
A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

GitHub Actions Pipeline Enumeration and Attack Tool

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Find and redact secrets in AI coding agent histories (Claude Code, and more).


Curated vulnerability writeups with full technical analysis, proof-of-concept scripts, IOC listings, and remediation guidance for real-world software…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

CVE-2024-38526 - Polyfill Scanner

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

Extension to grab github token from VSCode

Collect VEX documents and update VEX Hub

CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)

Find log4j for CVE-2021-44228 on some places * Log4Shell

PoC for CVE-2025-54416 tj-actions/branch-names command injection

node-ipc is malware / protestware!