Industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.
-
Updated
Sep 29, 2026 - Shell
Industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.
Full-spectrum security assessment tool for opencode — defensive code audit (17 vulnerability categories) + offensive penetration testing (63 attack categories, 15 agents, 11 domains). AI-powered AppSec, red teaming, and pentesting for vibe-coded apps.
All Labs of the Security for Developers Training
🛡️ Secure internal APIs with GitHub Actions OIDC workload identity. Implements a Zero Trust sidecar pattern using Envoy Proxy to replace static secrets with identity-based authorization.
8-phase API exploitation scanner — GraphQL, REST abuse, WebSocket, SOAP/XXE, rate bypass
Kong plugin to check Approov tokens.
Direct release of Android SDK versions for package inclusion
Source code for https://www.webapis.xyz/ developed using Hugo and a custom theme
Apigee X API Gateway labs: OAuth 2.0 flows, JWT auth, rate limiting, Shared Flows, API composition & CI/CD. Enterprise security patterns for Google Cloud Apigee.
A Zero-Trust orchestration sandbox demonstrating automated mTLS and secret rotation across Go and Python microservices.
AI agent skill for comprehensive security auditing of web apps, Supabase, databases, mobile apps, and APIs. Checks RLS policies, XSS/CSRF, exposed secrets, auth issues, OWASP Top 10, and more.
API-to-OT attack detection lab: crAPI + Conpot ICS honeypot + Grafana/Loki on Proxmox. Demonstrates BOLA, broken auth, and SSRF-to-OT pivot detection.
Simple Approov integration for the Mulesoft API Gateway
Frisk your HTTP routes for ungated mutating endpoints before you ship. A Claude Code skill that refuses done while a route that writes, pays, or triggers a job has no auth.
A demonstration of securing a Node.js Express API using OAuth 2.0 with PKCE, integrated with Keycloak as an Identity Provider, and deployed on Kubernetes. Features Role-Based Access Control (RBAC) and automated security testing scripts.
🕸️ GraphQL anti-pattern & security analyzer — query depth, N+1 resolvers, auth gaps, schema design. 90 patterns.
enterprise-like CI DAST for OSS/public-repo-friendly web/API targets, with lower adoption friction
Automated AI red-teaming and CTF-style experiment with direct backend API workflow and reproducible logs (INFO5995).
Capa de seguridad y autenticación con clave de 256 bits para la API WAHA local de envío de mensajes de WhatsApp.
To associate your repository with the api-security topic, visit your repo's landing page and select "manage topics."