Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely Self-hosted. Every model available on LiteLLM (Ollama, anthropic, openai...)
-
Updated
Aug 7, 2026 - Python
Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely Self-hosted. Every model available on LiteLLM (Ollama, anthropic, openai...)
A multi-vault secret injection tool for safely injecting secrets into app environment
Dependency Combobulator
A secure file system for your agents to execute code
♾️ Collection of DevSecOps Notes + Resources + Courses + Tools
Reapsaw is a continuous security devsecops tool, which helps in enabling security into CI/CD Pipeline. It supports coverage for multiple programming languages.
A quick script to spot the usage of Unicode Bidi (bidirectional) characters that could lead to an Invisible Backdoor
Hands-on secure code review training: learn to find vulnerabilities in Flask, Django, FastAPI through production-quality examples. Whitebox pentesting for modern web frameworks.
A controlled environment for demonstrating and understanding buffer overflow vulnerabilities in web applications. This project is designed for educational purposes as part of secure software development training.
A repository of Security Engineering exercises: these exercises are designed to prepare you for interviews.
Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.
Engineering best practices that AI coding agents actually apply — 40+ skills, from secure coding and cloud to compliance and UX writing. BUILD + AUDIT modes. Measured: best-practice coverage 59% → 98% vs. the same model unguided.
Learn web vulnerabilities — writeups, multi-language vulnerable/fixed code, OWASP Top 10 mapping, attack-path diagrams, and a runnable offline lab for each (SQLi, XSS, and more). For cybersecurity, AppSec, SOC, pentesters.
Real-World Security Conversations for AI Training
Host-agnostic pre-write security hook for coding agent: detects user-input patterns via Semgrep and emits deterministic, no-LLM security guidance.
Centralized STIG & NIST 800-53 compliance knowledge, playbooks, and secure code templates for federal systems development.
Secure-coding gates for AI-written code — 67 gates across 13 OWASP-aligned topics, checked before code ships.
Language- and framework-agnostic audit checklists for AI coding agents — security, correctness, and operability. Works with Claude Code, GitHub Copilot, Cursor, Codex CLI, OpenCode, and any agent that can read files.
A demo security vault application, for training and experimenting with OWASP and security tools.
Backend security Agent Skill that helps AI audit code, detect vulnerabilities, and generate secure-by-default backend applications, with deep Django/DRF coverage and guidance for any backend stack.
Add a description, image, and links to the secure-coding topic page so that developers can more easily learn about it.
To associate your repository with the secure-coding topic, visit your repo's landing page and select "manage topics."