Interactive Jupyter demo of Prisma AIRS detecting pickle deserialization attacks (CWE-502) in ML models. Educational security demonstration with ROI analysis.
-
Updated
Mar 25, 2026 - Jupyter Notebook
Interactive Jupyter demo of Prisma AIRS detecting pickle deserialization attacks (CWE-502) in ML models. Educational security demonstration with ROI analysis.
GH-300 live demo kit. A real Python app left intentionally immature (bugs, security gaps, low coverage) across 5 structured Copilot modules. Prompt library, Skills, AGENT.md, and a reset script included.
Intentionally vulnerable AWS Bedrock chat app for Prisma AIRS Red Teaming demos, with optional AIRS Runtime Security overlay for before/after testing.
Live PoC: MCP attacks that compromise AI agents mid-session and how to block them in a few lines of code.
A simple demo project for Spring Security
💥 ServerSideTemplateInjection (SSTI) Demo with Flask A simple Flask app to demonstrate Server-Side Template Injection vulnerabilities — useful for learning, testing, and understanding how SSTI works and how to avoid it.
Wishlist Member Arbitrary File Read via Directory Travesal <= 3.25.1
ProtonVPN Full Free — это надежное и простое приложение для безопасного доступа в интернет без ограничений по времени и объему трафика. Программа надежно шифрует ваше соединение, защищает конфиденциальные данные от перехвата и помогает легко открывать заблокированные сайты, сохраняя вашу полную анонимность в сети.
🛡️ Demo: Microsoft Defender for Cloud & GitHub Advanced Security (GHAS) integration - End-to-end vulnerability detection from code to cloud
🥒 Educational PyTorch pickle deserialization RCE demo showing how malicious .pt model files can execute arbitrary code during unsafe loading with torch.load().
Retail / e-commerce demo — intentionally vulnerable. Part of DevSecAI/arko-demos. Do not deploy.
Energy / smart-grid demo — intentionally vulnerable. Part of DevSecAI/arko-demos. Do not deploy.
Logistics / fleet-tracking demo — intentionally vulnerable. Part of DevSecAI/arko-demos. Do not deploy.
Pharma / clinical-trials demo — intentionally vulnerable. Part of DevSecAI/arko-demos. Do not deploy.
Healthcare / EHR demo — intentionally vulnerable. Part of DevSecAI/arko-demos. Do not deploy.
GovTech / digital-identity demo — intentionally vulnerable. Part of DevSecAI/arko-demos. Do not deploy.
Insurance / underwriting demo — intentionally vulnerable. Part of DevSecAI/arko-demos. Do not deploy.
Demo‑only non‑custodial stablecoin vault with commit–reveal claims.
ARKO Coverage Demos — a 10-application corpus that validates the ARKO decision engine across SAST, IaC, SCA, SBOM, and pipeline-misconfig detection. Each app is deliberately vulnerable for security tool testing.
SecureVulnApp – demo of common web‑security flaws and their mitigations
Add a description, image, and links to the security-demo topic page so that developers can more easily learn about it.
To associate your repository with the security-demo topic, visit your repo's landing page and select "manage topics."