Agent skill for producing threat models for open-source projects
-
Updated
Aug 19, 2026 - Python
Agent skill for producing threat models for open-source projects
Cut vuln noise to near-zero by proving which CVEs are actually callable from your app’s entry points, using open CLIs, reproducible SBOMs, and CI-first workflows.
Decision-support tool for analyzing domain/IP infrastructure profiles and prioritizing assessment efforts.
BountyDesk | Bugs, CVEs, bounties. Reproduced securely.
Read-mostly MCP server for Dependency-Track: AI-powered vulnerability triage with alias dedup, cross-project duplicate discovery, diff + carry-over between versions, and broadcast triage.
Public template repository for GitHub Copilot multi-agent workflows in industrial automation testing.
Reproducible Bandit alert-triage benchmark with a 949-row dataset, 265-row held-out split, classifiers, leakage checks, and published results.
Human-initiated security review workflow: deterministic scanning, agent-assisted triage, independent adversarial validation, and an evidence gate before any finding is confirmed.
AIG Simulation
Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075
OpenAI-powered white-hat security triage CLI and GitHub Action starter kit for open-source maintainers.
Reachability-aware CVE prioritizer: tells you which vulnerabilities are actually reachable from your code, and drafts the GitHub issue for the ones that matter.
Public defensive AI security profile and sanitized research examples
Privacy-first AppSec triage PoC: deterministic CI/CD gate + local-LLM (Ollama) audit layer, fail-secure by design.
To associate your repository with the vulnerability-triage topic, visit your repo's landing page and select "manage topics."