Agent skill for producing threat models for open-source projects
-
Updated
Sep 27, 2026 - Python
Agent skill for producing threat models for open-source projects
Cut vuln noise to near-zero by proving which CVEs are actually callable from your app’s entry points, using open CLIs, reproducible SBOMs, and CI-first workflows.
Decision-support tool for analyzing domain/IP infrastructure profiles and prioritizing assessment efforts.
BountyDesk | Bugs, CVEs, bounties. Reproduced securely.
Attacker-Reachable Sink Triage (ART) — A Kaggle Community Benchmark evaluating whether LLMs distinguish reachable code vulnerabilities from patched twins, safe logic, and vacuous noise.
Public template repository for GitHub Copilot multi-agent workflows in industrial automation testing.
AIG Simulation
Read-mostly MCP server for Dependency-Track: AI-powered vulnerability triage with alias dedup, cross-project duplicate discovery, diff + carry-over between versions, and broadcast triage.
Turn AI-assisted fuzzing crash artifacts into evidence-preserving duplicate clusters, reproduction states, and validation handoffs.
Human-initiated security review workflow: deterministic scanning, agent-assisted triage, independent adversarial validation, and an evidence gate before any finding is confirmed.
Static reachability analysis, can this function be reached from an external HTTP endpoint? Finds Flask routes, walks the call graph, and returns REACHABLE, NOT_REACHABLE or UNKNOWN with the exact path as evidence. Deterministic.
OpenAI-powered white-hat security triage CLI and GitHub Action starter kit for open-source maintainers.
Reproducible Bandit alert-triage benchmark with a 949-row dataset, 265-row held-out split, classifiers, leakage checks, and published results.
Free, self-hostable AI triage for FOSS security reports -- screens against a project's own documented defensive patterns
Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075
Reachability-aware CVE prioritizer: tells you which vulnerabilities are actually reachable from your code, and drafts the GitHub issue for the ones that matter.
Public defensive AI security profile and sanitized research examples
Privacy-first AppSec triage PoC: deterministic CI/CD gate + local-LLM (Ollama) audit layer, fail-secure by design.
To associate your repository with the vulnerability-triage topic, visit your repo's landing page and select "manage topics."