
Agent-Security-Regression-Harness
Executable security regression testing for agentic applications and MCP-integrated systems.

Executable security regression testing for agentic applications and MCP-integrated systems.

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a…

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and…

Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue…

Open-source cross-modal and multimodal prompt injection test suite. 250,000+ attack payloads across text, image, document, and audio modalities.…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…