242 packages matching “cwe-798”
oauthlint-rules
v0.11.1 · 28 days ago
Semgrep rules catching the OAuth, OIDC, JWT, and MCP security bugs that AI coding tools produce.
No known vulnerabilities
cwe-sdk
v1.1.19 · 1 year ago
A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC
No known vulnerabilities
@rigour-labs/core
v6.2.2 · 9 days ago
AI-native quality gate engine with local Bayesian learning. AST analysis, drift detection, Fix Packet generation, and agent self-healing across TypeScript, JavaScript, Python, Go, Ruby, and C#.
No known vulnerabilities
test-genie-mcp
v3.1.1 · 2 months ago
AI-powered app test automation MCP server - scenario generation, execution, detection, and auto-fixing
No known vulnerabilities
@strixgov/tool-gateway
v0.5.0 · 1 month ago
Local-first governed tool execution gateway for AI agents. Read/write classification, policy evaluation, signed execution receipts, multi-key rotation with cross-signed chain snapshots, per-capability rate limits, threshold-based escalation, file/webhook
No known vulnerabilities
@aeriajs/security
v0.0.305 · 3 months ago
This package implements common security checks. The checks can be used separatelly, or through a function called `useSecurity()`. This function returns an object with two functions:
No known vulnerabilities
aegis-squad
v1.8.0 · 18 days ago
Autonomous DevSecOps AI Engine. Combines OWASP SAST and OSV SCA dependency scanning with AI reasoning to eliminate false positives.
No known vulnerabilities
@security-alert/sarif-to-markdown
v1.11.1 · 8 months ago
Convert Sarif format to body text
No known vulnerabilities
cognium-dev
v4.9.24 · 17 hours ago
Static Application Security Testing CLI for detecting security vulnerabilities via taint tracking
No known vulnerabilities
fetch-cwe-list
v0.1.2 · 24 days ago
A simple Node.js module that fetches and parses the latest Common Weakness Enumeration (CWE) list
No known vulnerabilities
fetch-cwe-list-mcp
v0.1.0 · 24 days ago
MCP (Model Context Protocol) server exposing fetch-cwe-list tools for LLM agents. Experimental/alpha — APIs may change.
No known vulnerabilities
form-data-to-object
v0.2.1 · 1 month ago
Converts application/x-www-form-urlencoded keys to plain JS object
No known vulnerabilities
@clovnet/plugin-cli
v0.2.3 · 14 days ago
Clovnet plugin developer CLI — create, dev-loop (hot reload + live logs), lifecycle-test and publish plugins against a Clovnet runtime.
No known vulnerabilities
@oxpulse/intro-protocol
v0.2.4 · 1 month ago
L2 introduction protocol — Briar-faithful intro crypto (X25519+HKDF+AEAD), JSON+Zod wire codec, and Signal-style safety numbers. Fixes CWE-208 timing oracle in sessionId redundancy check. EXPERIMENTAL (0.1.0).
No known vulnerabilities
@aegisq-codeshield/security-rules
v2.2.0 · 2 months ago
AegisQ-CodeShield security rules — OWASP Top 10, OWASP LLM Top 10, CISA Secure by Design, CWE mappings
No known vulnerabilities
@microsoft/sarif
v5.7.0 · 27 days ago
SARIF SDK for Node.js: open-typed object model, region/snippet resolution, AI ruleId convention, and serialization helpers. Native TypeScript; no CLR dependency.
No known vulnerabilities
snyk-to-html
v3.7.9 · 1 month ago
Convert JSON output from `snyk test --json` into a static HTML report
No known vulnerabilities
@oxpulse/crypto-primitives
v0.5.1 · 1 month ago
Pairwise X25519+HKDF+AEAD primitives, XChaCha20-Poly1305, PQXDH hybrid KEM, MessageEnvelope v2 codec (authenticated binding transcript), and timing-safe comparison helpers for oxpulse-chat.
No known vulnerabilities
create-clovnet-plugin
v0.2.1 · 14 days ago
Scaffold a Clovnet plugin — thin alias for `clovnet-plugin create` (use via `pnpm create clovnet-plugin <name>`).
No known vulnerabilities
cwe-tool
v1.4.2 · 2 years ago
A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
No known vulnerabilities