R-U-DEAD-YET ?
Verifies Solid OIDC access tokens via their webid claim, and thus asserts ownership of a WebID.
Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs
Kubernetes RBAC Attack Path Visualizer — scan your cluster, detect attack paths, visualize in a local UI
supply chain attack poc
MCP server for accessing CIRCL CVE SEARCH API - search CVE data, vulnerabilities, and security information
Convert JavaScript to a javascript: URI bookmarklet. Standalone CLI, Node.js API, and grunt plugin.
This package provides a GraphQL directive `@rateLimit` for rate limiting GraphQL queries and mutations. This directive helps to prevent abuse and manage resources efficiently by limiting the number of requests a client can make within a specified time win
JSON Async
Cross-script confusable detection, slug safety, and LLM Denial of Spend defence. Zero dependencies.
Universal skill library for Claude, ChatGPT, Cursor, Gemini, and VS Code. Install once globally, use everywhere.
Security research — scope ownership proof for dependency confusion report
Security research — scope ownership proof for dependency confusion report
Shared types, constants, and utilities for Attack First Basketball
hint that that checks if external links disown the opener
Token-disciplined, methodology-first SDLC for the OpenAI Codex CLI.
Optional liveness-detection extension for expo-passkey: face presentation-attack-detection (PAD) gating for registration, authentication, and recovery flows
Multi-model security review for AI-generated code. Runs OpenAI, Anthropic, and Google reviewers in parallel and posts findings as PR comments.
Autonomous Minecraft agent powered by Featherless AI or Ollama
JavaScript/TypeScript class inheritance tools.
MeshCore hashtag GroupText packet brute-forcer with WebGPU acceleration and dictionary attacks
Secure-by-default MCP server with 5-layer validation for defense-in-depth protection
Node.js agent for Sqreen, please see https://www.sqreen.io/
Comprehensive security guards for LLM-powered and agentic AI applications - 34 guards covering OWASP Top 10 for LLMs 2025, Agentic Applications 2026, and MCP Security. All guards accessible via unified TrustGuard facade. Features prompt injection (PAP/per