A community-minded collective making AppSec and ASPM easier for developers.
We integrate the best open-source security tools, make them all speak the same language, and give the result back to the people who build them. No commercial goal. No upsell. No open-core paywall.
// why we build
A serious look at a single codebase can touch a dozen scanners — SAST, SCA, secrets, IaC, license, malware, DAST, CI/CD — and every one has its own CLI, its own flags, its own output shape, its own idea of what "severity" means.
Stitching them together is a tax every team pays again from scratch, and it lands hardest on the developers who just want to ship safe code.
So our mission is deliberately unglamorous: take the best open-source security tools, make them easy to run, make them all speak the same language, and give the result back to the community.
Find and fix issues in the code and its pipeline, as early and with as little friction as possible — where developers already work, not as a gate at the end.
Step back from a single repo to see security across a whole estate: what's exposed, where posture is improving or slipping, and what to fix first.
// projects
A modular security-scanning monorepo. One engine, many front-ends — an MCP server for agents/IDEs, a CLI for local & CI, a REST API + web app, and a continuous-scanning fleet with an ASPM dashboard. 20+ scanners, one normalized finding model, four report formats (JSON · Markdown · HTML · SARIF).
github.com/kubeek-sec/deep-scan ↗Canary endpoints — the only external addresses your code should contact during a security test. Non-malicious drop / exfiltration / info-collection paths that prove a hole exists before the fix, and is closed after. Hosted right here on kubeek.com.
github.com/kubeek-sec/canary ↗A security-scanner test bed. Intentionally-vulnerable fixtures, one CWE per directory, each paired with its remediation — plus DAST, LLM and CI/CD fixtures and centralized ground truth for benchmarking scanner recall and precision.
github.com/kubeek-sec/guinea-pig ↗cve-diff — builds a Parquet dataset that links every NVD CVE to its fixing-commit diff, its description and its CWEs. Auto-healing, parallel fetchers pulling patches from GitHub, GitLab, Gitee and cgit. The data behind smarter patch analysis.
github.com/kubeek-sec/patchnoisseur ↗// live on this host
This domain hosts the canary endpoints. They are not malicious — they only let a security test prove a drop / exfiltration / info-collection path exists before a fix, and is closed after.
| GET · POST | /info/ | Method / reachability echo — a simple outbound-HTTP beacon. |
| GET | /monip/ | Origin IP as seen across X-Forwarded-For, CF-Connecting-IP, REMOTE_ADDR. |
| GET | /run/download.php?file=run.sh | Drop via PHP by name — run.sh · run.ps1 · run.txt. |
| GET | /run/run.sh | Direct download of the inert staging script. |
Note: the served scripts are inert (echo "It runs!"). The site is fronted by Cloudflare, which rejects requests with no User-Agent (403) — always send one.
// get involved
Everything is open source. Star it, fork it, file an issue, or just read the code. Security should be a little less painful — for everyone.