12 Aug 2026
TypeScript
★ 17
Security Cards is an open-source tool providing library-specific security guidance for developers and AI coding agents, tailored to specific library versions, ensuring relevant and actionable advice. Its notable features include categorization by language, library, version, and security category, as well as the ability for agents to fetch and apply guidance seamlessly in their coding workflow. The tool enhances code security by offering secure rules and examples while clarifying that it does not replace professional security reviews.
12 Aug 2026
Python
★ 14
secpipw is an open-source Python package designed to enhance supply-chain security during package installation by acting as a safer wrapper around the standard pip command. It analyzes and mitigates supply-chain risks when installing packages, allowing users to use `spip install` as a drop-in replacement for `pip install` while still supporting additional package managers like pipx and poetry. This tool does not require configuration, aiming for ease of use while providing comprehensive checks against potentially malicious packages.
12 Aug 2026
TypeScript
★ 15
s-gw is a local credential management tool designed to enhance security for coding agents by allowing the approval of bounded actions while keeping raw credentials out of the model context and tool outputs. It facilitates the creation of typed handles for secrets, executes commands in a controlled child process with injected credentials, and provides sanitized output along with detailed audit evidence. Notable features include local custody of raw secret values, action-scoped access approvals, and a user-friendly console for monitoring activity and credential management.
12 Aug 2026
TypeScript
★ 58
Arcjet's example Next.js application showcases the integration of various security features designed to protect web applications with minimal code. Key capabilities include server-side email verification, bot detection, rate limiting based on user authentication, attack protection against SQL injection and cross-site scripting, and sensitive information handling. This tool serves as a practical demonstration for developers to implement and customize security measures effectively in their applications.
12 Aug 2026
Python
★ 53
DeepSafe is an all-in-one safety evaluation toolkit designed specifically for large language models (LLMs) and multimodal language models (MLLMs), integrating over 25 safety datasets along with the ProGuard evaluation model for comprehensive assessments. Its modular architecture allows for extensive customization and rapid integration of new components, promoting a streamlined, automated evaluation process that generates detailed reports to enhance AI safety research. Key features include a configuration-driven approach, facilitating user-friendly YAML-based execution and in-depth analysis capabilities, aimed at positioning itself as a significant tool in the construction of trustworthy AI systems.
12 Aug 2026
Python
★ 16
Assemblyline 4 - Service Base provides the foundational functionality for developing services within the Assemblyline 4 framework, facilitating the creation of new services via a provided template. Notable features include various image variants for stable and development builds, along with comprehensive documentation to guide service development. This tool is primarily utilized by developers looking to extend the capabilities of the Assemblyline platform in cybersecurity contexts.
12 Aug 2026
Python
★ 21
Assemblyline UI is a component of the Assemblyline 4 framework that provides a user interface along with various APIs and SocketIO endpoints for interaction and data retrieval. Its primary use case is to facilitate real-time information exchange about system alerts, submissions, and overall health through a consistent JSON output format. Notable features include a comprehensive set of APIs for data access and live updates via SocketIO for seamless user notifications.
12 Aug 2026
Python
★ 21
Assemblyline 4 - Core is a foundational service suite designed to manage and process submissions in cybersecurity workflows. Its primary use case lies in orchestrating various tasks such as alerting, archiving, dispatching, and managing service loads dynamically. Notable features include a scalable architecture, automated expiry handling, and comprehensive metrics generation to ensure effective monitoring and management of cybersecurity operations.
12 Aug 2026
Python
★ 158
AI for the Win is a hands-on training platform designed for security practitioners to develop AI-powered tools specifically for threat detection, incident response, and security automation. It features over 50 labs, including capstone projects and CTF challenges, focusing on practical applications such as phishing detection and security log analysis using advanced algorithms like Random Forest and LLMs. The platform also offers a Docker lab environment, sample datasets, and solution walkthroughs to facilitate immersive learning experiences.
12 Aug 2026
Python
★ 95
MalZoo is a mass static malware analysis tool designed to catalog malware samples by storing metadata in a MongoDB database and organizing samples into a directory structure based on their MD5 hashes. Its primary use cases include analyzing large sets of malware for insights (such as identifying compilation languages and packers) and monitoring emails for malicious attachments. Notable features include support for Docker and AWS Serverless deployment, extensive data collection capabilities, and integration options with tools like Splunk for enhanced analysis and visualization.
12 Aug 2026
Python
★ 17
Noctyra is an AST-based Python framework for code transformation and deobfuscation, offering a modular pipeline that simplifies complex expressions and logic in Python source code. Key features include the ability to resolve static values, unroll dynamic execution blocks, and optimize obfuscated constructs through a sequence of pluggable transformers. Designed for flexibility, it facilitates the analysis and processing of Python code while emphasizing the importance of running untrusted code in isolated environments for security.
12 Aug 2026
Python
★ 100
Mira is a mobile runtime detection workbench designed for iOS and Android, facilitating the analysis of real-time runtime conditions through reusable workflows and detection knowledge. Notable features include real app sandbox access, live logic execution capabilities, and fast setup for immediate results, enabling users to inspect and navigate app runtimes efficiently for enhanced security analysis. The tool integrates AI capabilities, allowing for a hands-on approach to runtime analysis and compounding detection intelligence from real findings.
12 Aug 2026
Python
★ 12
The Melitta Barista & Nivona for Home Assistant is a custom integration that enables the control of Melitta Barista T/TS Smart and various Nivona coffee machines via Bluetooth Low Energy (BLE) within the Home Assistant ecosystem. It allows users to monitor machine status, manage brewing recipes, adjust settings, and perform maintenance tasks through a unified dashboard, with additional features like an AI Coffee Sommelier for recipe generation accessible via conversation agents. The tool supports multiple languages and is designed to streamline the coffee-making experience through automation and integration with smart home setups.
12 Aug 2026
C++
★ 12
A dynamic Wii U mod loader.
12 Aug 2026
Python
★ 37
room-server is a server implementation designed to facilitate connectivity for the Wii no Ma platform. It primarily serves as a backend solution for users seeking to self-host the service, enabling enhanced multiplayer interaction and community features. Notable features include flexible self-hosting options and an open contribution policy that promotes collaborative development.
12 Aug 2026
YARA
★ 17
apihash_to_yara is a tool designed to generate YARA signatures based on Windows API hashes, facilitating malware detection and hunting through obscured imports. It allows users to extract API exports from DLLs and creates YARA rules with customizable thresholds for various hash variants, making it particularly useful against malware that utilizes API hashing techniques to evade detection. Notable features include support for custom API lists and the generation of multiple hash variants to enhance detection capabilities in malware analysis workflows.
12 Aug 2026
JavaScript
★ 14
ZeroKey is a self-hosted, OpenAI-compatible local AI proxy designed for interfacing with models like DeepSeek, Claude, and ChatGPT using personal credentials. It supports IDE integration, session persistence, and a range of built-in tools for enhanced functionality, allowing users to utilize AI capabilities directly from their development environments. Notable features include streaming responses, multi-IDE selection, and in-memory session tracking with support for custom tool calls.
12 Aug 2026
Python
★ 20
The UtechSmart Venus Pro Config utility is a reverse-engineered configuration tool for the UtechSmart Venus Pro MMO gaming mouse, specifically designed for Linux users. It allows for comprehensive device configuration, including button remapping, macro management, DPI adjustment, and RGB lighting customization, all without the need for Windows software. Notable features include a macro engine, battery monitoring, and a user-friendly interface that adapts to connected devices, ensuring effective management of mouse functionalities.
12 Aug 2026
Go
★ 63
Unleash is a comprehensive operator toolkit designed for managing local coding agents, providing functionalities for installation discovery, in-place binary patching, and configuration of operator authorization. It ensures the integrity and performance of tools like Claude Code and OpenAI Codex through features such as multi-install awareness, update survival mechanisms, and a robust safety model that includes timestamped backups and verification processes. With a flexible architecture that supports various platforms, Unleash enhances the operational capabilities of coding agents while safeguarding against disruptions during updates.
12 Aug 2026
Rust
★ 43
Sighook is a runtime patching library primarily designed for low-level software experimentation, reverse engineering, and custom instrumentation workflows. It enables instruction-level manipulation through features such as inline detours, byte patching, and callback mechanisms for capturing execution at specified instructions. Notable capabilities include support for multiple architectures (x86_64 and aarch64), and functions for instrumenting calls, restoring original bytes, and handling function-entry hooks, making it adaptable for diverse use cases across different platforms.
12 Aug 2026
Assembly
★ 26
IGI-Research-Data is a comprehensive repository that houses extensive research information and data pertaining to the Project I.G.I game, serving as a resource for educational purposes. It includes various data sections encompassing AI behaviors, game graphs, a detailed cheat engine table, and a multitude of structural analyses of game files, memory, and coding practices. Notable features comprise custom-built tools for compiling game binaries, visualizing graphs, and analyzing game natives, enhancing both research and exploration of the game's intricate systems.
12 Aug 2026
C++
★ 13
IzEngine is a cross-platform engine framework designed for creating modded game clients with flexibility and adaptability across various platforms and backends. It features a robust plugin system enabling dynamic module reloading at runtime and incorporates a just-in-time assembler for efficient code generation. This makes IzEngine particularly suitable for developers looking to enhance the gameplay experience through custom modifications.
12 Aug 2026
JavaScript
★ 19
DeepSpider is an AI-driven reverse engineering platform designed for JavaScript, enabling users to analyze encrypted links and reconstruct algorithms based on actual request evidence. It integrates OpenCode Agent, Patchright browser, and Chrome DevTools Protocol to provide a comprehensive environment for real-time analysis, effortless debugging, and the generation of runnable scraping code, while ensuring validation through multi-sample comparisons. Its notable features include progressive analysis of obfuscated code, direct browser interactions, a structured eight-stage workflow for reverse engineering, and support for seamless transitions between browser and standalone environments.
12 Aug 2026
C++
★ 28
CoD4 DM1 is a tool designed for the reverse engineering of CoD4 and CoD4X `.DM_1` demo files, facilitating the parsing of snapshot information, gamestate, frames, entities, clients, and server messages. Notable features include support for CoD4 & CoD4X protocols, Huffman coding for CoD4 and Q3, and a demo reader API, enabling extensive analysis of game data. The tool is accessible as a command-line interface and a library, and is available for integration via vcpkg.
12 Aug 2026
C++
★ 328
CoBRA is a Mixed Boolean-Arithmetic expression simplifier designed to deobfuscate complex arithmetic expressions that interleave arithmetic, bitwise, and shift operators, often used in software obfuscation. It employs a worklist-based orchestrator and features various techniques such as signature-based analysis, semilinear processing, and decomposition to simplify expressions efficiently. Notable functionalities include verification via spot-checking or Z3 proofs and the ability to handle weighted sums of bitwise atoms, making it a robust tool for analyzing obfuscated code.