Here are
20 public repositories
matching this topic...
Outside-in replication of Anthropic's Mythos Preview / Project Glasswing — open-source agentic vulnerability-discovery scaffold on Claude Opus 4.7. Eight-phase sink-guided pipeline, ~$1/run, OSS self-scan and coordinated disclosure.
Updated
May 4, 2026
Shell
A nonprofit, open-source vulnerability disclosure platform built for security researchers.
Updated
Jun 23, 2026
Python
The Internet Observatory (Obsrva) is a vulnerability research project founded by independent security researcher Tyler Butler. Obsrva engages product vendors in coordinated disclosures, publishes vulnerability advisories, and creates proof of concept exploits.
Updated
Oct 23, 2021
JavaScript
Claude Code skill for auditing web apps for security vulnerabilities. Detects inside-codebase vs outside-black-box, runs the right checklist, sweeps server/infra, deep-dives rate-limit posture. 14 PoC probe templates + deep ripgrep recipes.
CISA Advisory ICSA-26-183-03 - Gardyn IoT Hub - 3 CVEs (companion to ICSA-26-055-03)
The answer is probably a vulnerability. Autonomous vulnerability research for a mostly insecure galaxy.
Updated
Jul 22, 2026
Python
Security analysis toolchain for open-source AI agent frameworks: custom semgrep rules, scan pipeline, coordinated-disclosure workflow.
Updated
Jul 2, 2026
Python
[MIRROR] Managing Sensitive and High-Risk Incidents with Confidence and Reliability.
CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)
CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)
CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-32662: Active Debug Code in Production — Gardyn Home Kit (ICSA-26-055-03)
CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)
SHA-256 hook-integrity verification I shipped to rtk-ai/rtk (PR #119) — hardening the agent auto-approve hook against hijacking.
CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)
CVE-2025-1242: Hardcoded iothubowner Connection String — Gardyn Home Kit (ICSA-26-055-03)
CISA Advisory ICSA-26-055-03 (Update B) — Gardyn Home Kit IoT Vulnerabilities — 10 CVEs (companion advisory ICSA-26-183-03, +3 CVEs)
CVEs and security advisories I have reported - write-ups, proof of concept and evidence, published once the fix is out.
Updated
Jul 24, 2026
Shell
CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)
Improve this page
Add a description, image, and links to the
coordinated-disclosure
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
coordinated-disclosure
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.