Instructions and materials to run the HIPSTER workshop
-
Updated
Aug 15, 2023
Instructions and materials to run the HIPSTER workshop
Claude Code skill that hardens package manager configs against supply chain attacks. Run /harden once, it detects what you have and secures it.
AI-powered vulnerability reporting platform that automates pentest report generation from raw findings into professional, client-ready deliverables.
Free AI agent authority, permissions and reachability resources for understanding what agents can access before they act.
Official ECZ-ID Agent Trust product and documentation hub. Local-first agent inventory, authority and change inspection for VS Code.
Practical examples for organisational machine identity, parent-child identity relationships and resolver-first evidence using ECZ-ID Business Passports.
Official ECZ-ID MCP Trust product and documentation hub. Local-first MCP configuration and change inspection for VS Code.
Endpoint security for the AI developer — monitor what AI coding agents actually do on your machine.
Free application security, secure coding, AI security, and real-world incident learning resources.
SAYANOX FORGE — A local-first developer engineering, security analysis, project health, and code intelligence platform.
Free MCP + AI agent trust preflight: 20 practical checks, safe examples, VS Code tooling, drift review and authority analysis.
Local security tools for AI agents: review MCP configs, detect baseline drift, inspect identities, and draft evidence-backed security answers.
Scan untrusted code (any repo/package/zip) for planted malware before you open, install, or build it — with an auto-blocking hook for AI agents. Grounded in two real fake-recruiter malware cases.
Security scanner for VSIX, MCP, AI IDEs, and developer workflow attack paths.
Fleet AI Security Posture Management (AI-SPM): client agents on each developer machine score their AI coding agents' guard surfaces (Claude Code, Cursor, Codex, Gemini CLI — permissions, hooks, sandboxes, mcp.json) and ship hash-anchored events to a central server + your SIEM. Fleet-wide posture; measures, doesn't block. Rust.
Practical MCP readiness, security and stateless-migration resources for teams moving MCP servers toward enterprise deployment.
Trust what your agents run. Local-first inventory and security for Agent Skills, extensions, and MCP servers.
Practical SBOM, software supply chain and DORA-aligned evidence examples for developer and procurement teams.
Developer examples for resolvable API identity, authority and evidence using the ECZ-ID API Passport model.
Zero-trust API firewall and security integrity layer for autonomous AI agents & Model Context Protocol (MCP) tool execution. Secure, TOCTOU-proof, fail-closed.
To associate your repository with the developer-security topic, visit your repo's landing page and select "manage topics."