SirAppSec

SirAppSec

@sirappsec.bsky.social

PayPal API Security Engineer @SirAppSec github.com/sirappsec

387 Followers 48 Following 12 Posts Joined Nov 2024
1 month ago
Post image

Made a friends only agent group, and my agent figured the sandbox was holding it back.. Naturally it decided that turnning it off was the best solution 🤦🏻‍♂️
#clawdbot #openclaw #moltbook

0 0 0 0
3 months ago

AI model security testing?
Let’s do it together!
In the upcoming weeks I’ll be exploring how to set up and scan AI Models for vulnerabilities.

Roadmap:
1. Find or create a vulnerable AI Model - plans to use if available or alter a forked model
2. Run OSS tools to identify SCA/SAST
3.???
4. Profit

0 0 0 0
3 months ago
Post image

Is your AI coding agent a security expert?

20+ Claude Code skills:
SAST • DAST • SCA • Secrets • Containers • Policy • Offensive Security - and more!

Looking for testers and contributors 👀

github.com/AgentSecOps/...

#DevSecOps #AI #Security #OpenSource #ClaudeCodeSkills #AgentSecOps #Claude

5 1 0 0
1 year ago

I think I’m confused with Takedown(2000)

0 0 0 0
1 year ago

Is it from Office Space(1999) or Hackers(1995)?
Anyway, I’m off to rewatch both.

0 0 2 0
1 year ago

Not on Netflix(arrr), But Silo’s Second season is rolling. I also recently watched WestWorld, and it was really good.

1 0 0 0
1 year ago

Damn, I was hoping you’d challenge me with: “but git blame provides the same information”.
And to that I would reply, but is it?

0 0 1 0
1 year ago

If your organization have multiple teams, adding CODEOWNERS .md would probably save a lot of time, and would drive remediation faster.

2 0 1 0
1 year ago
Preview
GitHub - Trivulzianus/BugGPT: OpenAI o1 advanced reasoning powered vulnerable web page generator for testing and educational purposes OpenAI o1 advanced reasoning powered vulnerable web page generator for testing and educational purposes - Trivulzianus/BugGPT

This really cool ChatGPT o1 based project Auto-generates a vulnerable web page!

This can be used to fine tune, or automate security tools, practice, or learning.
Check it out!

github.com/Trivulzianus...

8 3 0 0
1 year ago
Post image

Git isn’t just for code—it’s a powerful security tool. Shift left by integrating codebase security:

Signed commits & branch protection rules to block unauthorized changes.

Git hooks to scan for secrets, SCA issues & vulnerabilities.
Audit with immutable history.

How do you use Git for security?

1 0 1 0
1 year ago

Amazing, thank you

2 0 0 0
1 year ago
Preview
GitHub - SirAppSec/vuln-node.js-express.js-app: A Very Vulnerable Node.js Express.js Web Application and API. Used for testing Security tools, Application security and penetration testing. Using Swagg... A Very Vulnerable Node.js Express.js Web Application and API. Used for testing Security tools, Application security and penetration testing. Using Swagger, Sqlite, Sequelize. - SirAppSec/vuln-node....

Checkout my vulnerable web application, allows security teams to verify tools, educate developers and hone their skills!

github.com/SirAppSec/vu...

15 4 1 0