
attestd | CVE API for Machine-Readable Vulnerability Risk Signals
将CVE漏洞数据转换为机器可读风险信号的API,用于自动化。
robert_marshall5 · Product Hunt
attestd CVE and supply chain risk signals for autonomous AI agents.
完整作品展
技术栈
60 projects

将CVE漏洞数据转换为机器可读风险信号的API,用于自动化。
robert_marshall5 · Product Hunt
attestd CVE and supply chain risk signals for autonomous AI agents.

Vulnsy是为安全团队提供的渗透测试报告平台,可10倍快速交付客户报告。
@TurvSec · X

为网络设备自动备份配置并用E2EE端到端加密保护。
Willdom1986 · V2EX
多年前考过 CCNP 网络工程师,以前有一个很头疼的地方就是网络设备配置丢失引发的各种故障。后来越发觉得,网络设备的配置实际上是一个非常关键的数字资产。 为此,我利用周末时间开发了 XConf ( https://xconf.ai) 来解决这个问题。 产品主要就是想解决两个问题:**自动化的灾备高可用**,以及**端到端的安全**。 * **自动备份与灾备**:支持将配置定时备份到云端。如果网络断连了,探针会自动在本地离线队列里暂存配置,等连接恢复后自动重传。 * **端到端加密**:本地的 Go 探针是完全开源的,会自动在内存中对密码进行流式脱敏,并在上传前通过 AES-256-GCM 在本地加密。SaaS 后台拿到的只有密文,解密和版本比对( Diff )都完全在你的浏览器本地沙盒里通过 WebCrypto API 进行。 * **打磨版的配置对比 Diff**:我花了一些功夫打磨了浏览器端的配置版本对比功能,力求让日常比对的交互体验足够丝滑。 * **AI 安全基线审查**:系统集成了 AI 辅助的安全基线审查,可以一键检查和分析配置中的潜在风险。 因为目前完全是我利用业余时间(主要在周末)维护,所以确实没精力提供工作日的在线即时客服。大家使用过程中遇到任何 Bug ,欢迎随时去 GitHub 提 Issue ,我会在周末集中修复和跟进。 目前公测已开放,不需要邀请码即可注册,欢迎大家体验吐槽。 探针 agent 开源地址: https://github.com/willdom-lee/xconf-agent 官方网站: https://xconf.ai

AI 应用安全扫描器,检测泄露的密钥和配置问题。
thfothijn · Product Hunt
OpzyAI Finds what your AI-built app leaks — your editor fixes it

使用AI增强的安全分析扫描代码和应用漏洞。
u/swifi_ai · Reddit
After 10 years of keeping this idea alive, I finally launched my AI security platform to beta After more than 10 years of keeping this idea alive in one form or another, I finally pushed Swifi live to beta: https://swifi.ai Swifi is an AI-augmented application security platform. The goal: combine traditional security scanning with AI so teams can understand risk across code, vulnerabilities, and production context without stitching together a dozen disconnected tools. Why now? AI change

监控外部攻击面、检测子域名暴露、自动映射 CVE 威胁。
@tugayakin34 · X
ThreatPort is an all-in-one Cyber Threat Intelligence & Attack Surface Management platform

扫描你的应用中泄露的API密钥、开放数据库和身份验证绕过。
@Nqspq · X
been building a security scanner for vibe-coded apps — it catches leaked API keys, open databases, logins you can bypass. tested it on a repo made for testing scanners. it caught everything — report below free if you want to check yours:

VibeLint 为 AI 代理提供代码检查、权限控制和审批工作流。
@RElharrak39428 · X

扫描AI应用发现安全和代码质量问题,自动生成GitHub修复。
@LaunchGuardHQ · X
I'm an HVAC installer, not a developer. Built LaunchGuard nights & weekends with AI coding tools. It scans AI-built apps for leaked API keys, wide-open databases, and vulnerable dependencies — then opens a real GitHub PR with the fix.

Veridome Surface:扫描AI应用部署的安全问题并生成修复。
maor_dayan_ · Product Hunt
Veridome Surface The security layer for apps you built with AI

用AI分析应用程序的安全漏洞和风险。
@DavidFilbey · X
I Built primarily using models from @AnthropicAI. However, I’m now completely unable to use any of the models to continue working on this app due to the extremely aggressive censorship and “guardrails” implemented. I have a premium subscription to Claude Code and Cursor. I’m curious to know if @cursor_ai or @AnthropicAI can provide a solution to allow me to continue using Anthropic models to develop legitimate security software products. Alternatively, I’d appreciate any recommendations you may have.

探索2020年以来的CVE趋势和漏洞严重性,按报告组织分类。
u/Secret_Appeal6271 · Reddit
Agents are more capable, and susceptible to exploits, than ever. We're working to stop this from hurting users. AI agents are starting to get real access like GitHub tokens, cloud credentials, customer data, deploy permissions. Not coincidentally, the rate of major cybersecurity incidents is rising rapidly. See for yourself: https://epoch.ai/data/cve?view=graph https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/ My friend and I, both AI researchers, are working o