
sec-af
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

Security training for the apps you actually ship. Open your browser and start hacking.

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Script to audit GitHub Action Workflow files for potential vulnerabilities.

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

CVE-2020-8809 and CVE-2020-8810

GameLoop update MITM

Open source solutions for SOC2, GDPR, and ISO27001


A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Exploit for CVE-2024-0402 in Gitlab