
sec-af
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

🛡️ Scan and assess vulnerabilities in Next.js/Waku with the CVE-2025-55182-Scanner, combining static and dynamic analysis for robust security.

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A static analysis security vulnerability scanner for Ruby on Rails applications

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…