
prismor
Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

German OWASP Day conference site & presentation archive

An open, vendor-neutral verification standard for traceable, reviewable, and rights-aware open-source intelligence. Current release: OOVS v0.1.0.

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…


OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

OWASP Thick Client Application Security Verification Standard

OWASP Secure Agent Playbook Project

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

MAPS cloud scanner and response parser for Microsoft Defender research.