基于函数级污点分析的 Java 源代码漏洞审计工具JavaSinkTracer,通过 Model Context Protocol (MCP) 为 AI 助手提供安全分析能力。
☆115Oct 7, 2025Updated 10 months ago
Alternatives and similar repositories for JavaSinkTracer_MCP
Users that are interested in JavaSinkTracer_MCP are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 基于Python javalang库开发的一款轻量级Java源代码审计工具,by Tr0e☆75Oct 23, 2025Updated 9 months ago
- Fenrir 是一个基于 MCP 协议与 AST 技术的代码审计工具,旨在解决安全研究与自动化代码审计领域中,面对大规模、结构复杂甚至反编译代码时,传统代码搜索与分析手段效率低、准确性差的问题。☆179Oct 21, 2025Updated 9 months ago
- 一款基于Zjackky/CodeScan的轻量级匹配Sink点并AI审计的代码审计扫描器☆253Feb 13, 2025Updated last year
- Web 安全渗透测试工具,包含端点发现、跨域消息追踪、原型污染检测、词表生成和 DOM XSS 检测☆33Feb 1, 2026Updated 6 months ago
- VigilantX 是一个专为 Burp Suite 设计的被动式 XSS(跨站脚本)漏洞检测扩展。该工具采用创新的两阶段检测机制,能够高效、准确地识别 Web 应用中的 XSS 漏洞,并通过飞书 Webhook 实时推送漏洞发现通知。☆21Sep 12, 2025Updated 10 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Privacy Check Go☆25Feb 11, 2026Updated 5 months ago
- 专注于代码审计skill,最小化轻量化skill,只负责安全边界。☆993Jun 16, 2026Updated last month
- Detect and fix semantic traps in Claude Skills that cause LLM hallucinations☆25Mar 8, 2026Updated 5 months ago
- JavaGadgetGenerator 工具,支持 ysoserial,Hessian,字节码,Expr/SSTI,Shiro,JDBC 等 Gadget 生成,封装,混淆,出网延迟探测,内存马注入等...☆576Apr 3, 2026Updated 4 months ago
- AI驱动的代码漏洞自动化审计,于业界公开的实现思路汇总、跟踪与分析_By Tr0e☆33Jan 23, 2026Updated 6 months ago
- ☆849Feb 13, 2026Updated 5 months ago
- Claude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析☆138Mar 20, 2026Updated 4 months ago
- Java Vulnerability Exploitation Platform☆2,140Updated this week
- fastjson利用,支持tomcat、spring回显,哥斯拉内存马;回显利用链为dhcp、ibatis、c3p0。☆330Mar 15, 2022Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- 记录一些代码审计过的源码☆182Feb 26, 2025Updated last year
- 一款轻量级匹配Sink点的代码审计扫描器,为了帮助红队过程中快速代码审计的小工具☆402Oct 6, 2024Updated last year
- 记录一下 Java 安全学习历程,也算是半条学习路线了☆1,385Jun 26, 2025Updated last year
- Java bytecode analysis engine built on ASM, extracts method call graphs, inheritance trees, Spring routes, and string constants from JAR/…☆48Mar 20, 2026Updated 4 months ago
- 一个基于LLM的多Agent全流程漏洞挖掘项目,支持PHP、Java、Python、Go、Node.js等多种语言项目环境搭建、漏洞分析、漏洞验证、报告产出。支持多Agent并发高效率沟通完成漏洞挖掘任务。☆168Apr 25, 2026Updated 3 months ago
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队 成员的工作流程,提升攻防效率☆1,570Updated this week
- ☆131Dec 8, 2025Updated 8 months ago
- ☆266Mar 31, 2026Updated 4 months ago
- ☆197Mar 31, 2026Updated 4 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- 一个用于检测HOST 头攻击漏洞的Burp Suite扩展插件。☆13Mar 7, 2025Updated last year
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞,实战导向,助力安全研究与合规检测。☆1,042Jul 31, 2026Updated last week
- A lightweight active and passive scanner that combines the advantages of local and distributed models, supports dynamic external plugin i…☆367Feb 5, 2026Updated 6 months ago
- 🔍 CodeAuditAssistant - JetBrains Code Audit Plugin (Beta) ⚡ Deep Call-Chain Tracking | 🚀 Method/Class Search | 🔥 Prebuilt Vuln Sink…☆786Mar 14, 2026Updated 4 months ago
- 对Auth/Waf 自动化bypass的burpsuite插件☆1,311May 10, 2026Updated 3 months ago
- 漏洞挖掘小工具,用于发现页面中的隐藏可点击元素☆85Jun 4, 2025Updated last year
- 红帆OA iOffice.net udfmr.asmx接口处存在SQL注入漏洞☆12Jun 16, 2023Updated 3 years ago
- FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用☆1,244Jul 12, 2024Updated 2 years ago
- 基于Java开发的代码字符串搜索工具,用于辅助快速代码审计,筛选危险方法名称搜索代码中可能存在的漏洞☆39Mar 7, 2026Updated 5 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Nacos Derby命令执行漏洞利用脚本☆154Apr 7, 2025Updated last year
- IDEA代码审计辅助插件(深信服深蓝实验室天威战队强力驱动)☆584Mar 10, 2025Updated last year
- CVE-2022-22947注入哥斯拉内存马☆28Jun 21, 2023Updated 3 years ago
- Java 代码审计-存在风险的函数汇总。方便我们日常代码审计过程中快速定位漏洞点,配合静态代码分析工具做到事半功倍。Java code audit - summary of risky functions. It is convenient for us to quickl…☆30Jul 16, 2024Updated 2 years ago
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆510Jan 12, 2026Updated 6 months ago
- 微信小程序全自动安全审计 Skill,基于 Claude Code Agent Teams。7 Agent 协作,覆盖敏感信息、API接口、加密分析、漏洞分析四大维度。采用脚本+LLM双层架构,脚本保证覆盖率,LLM保证准确率。☆376Apr 3, 2026Updated 4 months ago
- AI 驱动的多 Agent 自主代码安全审计:审计计划、危险 Sink 发现与调用链分析;AI-driven multi-agent autonomous code security auditor — audit planning, sink discovery & ca…☆96Aug 1, 2026Updated last week