
lurkx - Exposure workspace
Search and analyze breach data, threat feeds, and exposed credentials from a single workspace.
@alencristen · X
The full gallery
Tech stack
22 projects

Search and analyze breach data, threat feeds, and exposed credentials from a single workspace.
@alencristen · X

Monitor your Supabase logs for security issues like credential stuffing and exposed keys.
@DefencecorHQ · X
Your app has been live for months. Your last log check was launch day. Defencecore monitors your Supabase activity and surfaces what needs attention—so you don’t have to live in the logs. #vibecoding #ai #supabase

SecretSweep finds leaked API keys, passwords, and credentials across your GitHub, GitLab, and Bitbucket repositories.
@MaksimHaydwv7j · X

Scan websites for accessibility and privacy compliance issues using AI.
@tobio_ojebiyi · X

Find security issues in AI-built apps: exposed tables, leaked keys, and client-side auth checks.
@Sentrint · X
Made Sentrint after seeing how many vibe-coded apps ship with RLS switched off. Point it at a GitHub repo and it finds open user tables, exposed keys and auth checks that only run in the browser. Free scan is the whole scan, no card.

Secure client portal for sharing files, answers, and approvals with real-time status visibility.
@danielkleach · X
is a branded client portal for files, answers, sign-offs, and signatures. No more scattered email threads, docs in Google Drive, or confusion about who is waiting for whom. Business and client both see what is done and what is in progress on both sides, in

Analyze Hacker News profiles with your own LLM API key, fully client-side.
Topfi · HN
Like everyone on HN, I love nothing more than to (re)read my own comments. Getting my intuition that I am among the smartest, most humble, highest quality commenters on here confirmed by an LLM so capable that the US government had to temporarily export restrict it [0] seemed only natural. Having had my perfection confirmed, I decided to share this joy with you as I had a few percent usage left before a reset. I took a few prompts, then did a review of the output which resulted in Selbstbild, a BYOK (Anthropic / OpenRouter) web app that gives you a summary and assessment of your public comments by one of our machine Gods, including Fable 5 (provided your can afford that luxury at API pricing). In all seriousness, I have, for a long time, used my own comments on social media (including HN) as part of a personal needle-in-haystack test, simply because I do know my somewhat peculiar style and what I tend to write, but also because I can sometimes write in a slightly confusing manner, ma

Monitor your external attack surface, detect subdomain exposures, and map live CVEs automatically.
@tugayakin34 · X
ThreatPort is an all-in-one Cyber Threat Intelligence & Attack Surface Management platform

Find exposures in your external attack surface before intruders exploit them.
@OGVeilScan · X

Secure GitHub pull requests with hardware authentication and OTP verification.
jallmann · HN
> want without a PR process that requires hardware authentication or proof of presence Just curious, what do you use for this? I built OTP Guard [1] a few years ago for exactly this problem, although I haven't seen any alternatives in the space. Does GitHub have something built-in now? The original framing was more "local malware compromising your GitHub account" ... it never occurred to me that the malware could be a LLM. I really should update the page. [1] https://otpguard.com

Hide sensitive images with client-side pixelation that only you can restore.
mqx · V2EX
图片转马赛克网站 简介:可以把敏感的图片生成马赛克,然后发送给别人,别人再上传还原,纯前端(隐私安全) 网站地址: https://e5660498.pinme.dev/ 放一张测试图片在一楼

Real email inbox, login automation, OTP handling, and credential vault API for AI agents.
u/kumard3 · Reddit
shipped delivered/bounced/replied webhooks, and deliberately left out open-pixel tracking an agent that sends mail needs to know what happened to it. i had delivery and bounce events sitting in the database the whole time, they just never got delivered anywhere useful, so an agent sending mail had no way to react to a bounce or know if anyone replied. shipped webhooks for the real lifecycle: delivered, bounced, complained, replied. an email.replied event fires specifically when an inbound