Starred repositories
Opinionated Oxlint rules for rejecting low-evidence TypeScript and JavaScript patterns
kidd / org-gcal.el
Forked from myuhe/org-gcal.elOrg sync with Google Calendar. (active maintained project as of 2019-11-06)
EvenBetter is a frontend Caido plugin that makes the Caido experience even better 😎
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
DeepSeek 4 Flash and PRO local inference engine for Metal, CUDA and ROCm
SpaceXAI's coding agent harness and TUI. Fullscreen, mouse interactive, extensible.
The agent that grows with you
dscode is a coding agent that empowers digital and knowledge work. It uses MCP to connect creative workflows with the coding agent, and provides a web UI to support and showcase a variety of digita…
Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents
A fancier postMessage tracker with Chrome Manifest version V3 support and a few additional features, inspired by Frans Rosens postmessage tracker.
Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.
Agentic AI security tool that applies proactive, attacker-first analysis directly to source code.
GQLSpection - parses GraphQL introspection schema and generates possible queries
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…
Find, verify, and analyze leaked credentials
Build interactive web apps in Python. No JavaScript required.
jxscout superpowers JavaScript analysis for security researchers
Collection of documentation, tools, and tips related to vulnerability research.
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if hand…
Simple "postMessage logger" Chrome extension
Interactive XSS Labs to get into Client-Side Hacking
RoguePlanet Windows Defender Vulnerability