Detect drift. Defend cloud.
-
Updated
Feb 21, 2026 - Go
Detect drift. Defend cloud.
Encrypted vault, ZK settlement archiving, x402 payment receipts, Agent Passport binding, and Solana anchoring for OpenClaw and agent runtimes. Drop-in stack — compression, privacy, payments, identity.
AI-powered multi-chain Web3 security toolkit. Scan smart contracts across 6 EVM chains in minutes, not weeks.
Interactive React/Vite portfolio for Tasfiya Tabassum — useful experiments, security tooling, systems work, and the modern web.
Security Notes/Tools/Scripts
Native DeepSeek Harness workbench for evidence-first vulnerability research, reproduction, and reporting.
Client-side AWS IAM policy blast-radius analyzer (fail-closed). Web tool live; headless CLI + SARIF + GitHub Action in progress.
Deterministic, local-first context builder for flow automation exports: redacts sensitive data, detects risks, and produces auditable bundles for AI assistants and support workflows: flow analysis, subflow expansion, secret redaction, token budgeting, and reproducible bundle generation via CLI and VUE web app.
Local-first context-integrity engine. Reconstructs trust from immutable runtime history, contains risky actions in QTF, and gates promotion through EXT.
Automated reconnaissance and attack-surface analysis pipeline for infrastructure visibility, asset discovery, and vulnerability identification.
Production-grade scripts to deploy, harden, and operate OpenCTI on Ubuntu LTS with the fixes for issues you'd otherwise hit on day one.
High‑performance iocx plugin for detecting Windows Registry keys, values, and persistence locations. Includes full test coverage, performance benchmarks, and security checks.
ProtoAudit is a research-grade toolkit for protocol behavior analysis, cryptographic metadata inspection, and randomness anomaly detection. It helps to identify protocol misuse patterns such as challenge reuse, retry loops, deterministic randomness, and handshake inconsistencies. Designed for protocol research, security analysis, and CTF tasks.
Defense shield for the Agent2Agent (A2A) protocol: SSRF-guarded push webhooks, per-operation capability tokens, signed Agent Card verification and covert-collusion detection. AGPL-3.0.
A research instrument working toward one map of detection knowledge — the major rule libraries, where they intersect and where they don't, resolved against MITRE ATT&CK.
Educational C2 Framework for Red Team Learning
Deterministic Python CLI for repository hygiene checks and pre-commit secret scanning.
behavior based cve detection for react server components
Developer-first security automation tool that orchestrates SAST, secrets scanning, and dependency scanning with CI security gates.
Access Log Correlator - Python based access log correlation tool for detecting failed login bursts with schema validation and JSON output.
To associate your repository with the security-tooling topic, visit your repo's landing page and select "manage topics."