Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely Self-hosted. Every model available on LiteLLM (Ollama, anthropic, openai...)
-
Updated
Jun 26, 2026 - Python
Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely Self-hosted. Every model available on LiteLLM (Ollama, anthropic, openai...)
A multi-vault secret injection tool for safely injecting secrets into app environment
Dependency Combobulator
A secure file system for your agents to execute code
♾️ Collection of DevSecOps Notes + Resources + Courses + Tools
Reapsaw is a continuous security devsecops tool, which helps in enabling security into CI/CD Pipeline. It supports coverage for multiple programming languages.
A quick script to spot the usage of Unicode Bidi (bidirectional) characters that could lead to an Invisible Backdoor
Hands-on secure code review training: learn to find vulnerabilities in Flask, Django, FastAPI through production-quality examples. Whitebox pentesting for modern web frameworks.
A controlled environment for demonstrating and understanding buffer overflow vulnerabilities in web applications. This project is designed for educational purposes as part of secure software development training.
Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.
A repository of Security Engineering exercises: these exercises are designed to prepare you for interviews.
Learn web vulnerabilities — writeups, multi-language vulnerable/fixed code, OWASP Top 10 mapping, attack-path diagrams, and a runnable offline lab for each (SQLi, XSS, and more). For cybersecurity, AppSec, SOC, pentesters.
Real-World Security Conversations for AI Training
Java Security Education Framework (JSEF) 是基于Spring Boot 3.x构建的Web安全实践平台,专为开发者、安全研究员、高校学生及企业培训设计。通过35+种真实业务场景下的安全漏洞实例(含注入攻击、越权访问、敏感信息泄露等核心类型),提供“原理讲解→漏洞复现→代码对比→修复验证”的完整学习闭环,帮助学习者从“理论”到“实战”快速掌握Web安全核心能力。
Engineering best practices that AI coding agents actually apply — 40+ skills, from secure coding and cloud to compliance and UX writing. BUILD + AUDIT modes. Measured: best-practice coverage 59% → 98% vs. the same model unguided.
Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.
Centralized STIG & NIST 800-53 compliance knowledge, playbooks, and secure code templates for federal systems development.
Secure-coding gates for AI-written code — 67 gates across 13 OWASP-aligned topics, checked before code ships.
A demo security vault application, for training and experimenting with OWASP and security tools.
Language- and framework-agnostic audit checklists for AI coding agents — security, correctness, and operability. Works with Claude Code, GitHub Copilot, Cursor, Codex CLI, OpenCode, and any agent that can read files.
Add a description, image, and links to the secure-coding topic page so that developers can more easily learn about it.
To associate your repository with the secure-coding topic, visit your repo's landing page and select "manage topics."