


Repo demonstrating CVE-2021-43616 / https://github.com/npm/cli/issues/2701

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Agent-Isolated Credential Broker for AI Agents



Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

Open source vulnerability DB and triage service.

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE


Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228