This page features open-source application security projects, mostly with an AI focus. Topics include threat modeling, secure code assistant, security reviews, and secure-coding guidance.
- appsec-advisor — A Claude Code plugin that builds STRIDE threat models from repository code and configuration. It also supports requirements audits, change reviews, and CI gates. Currently in beta.
- appsec-advisor-examples — Example threat models produced by appsec-advisor for deliberately vulnerable apps such as OWASP Juice Shop, available as Markdown, HTML, PDF, YAML, SARIF, and Threat Dragon files.
- appsec-advisor-tools — Companion scripts for running appsec-advisor threat modeling from a terminal, cron job, or CI pipeline, with repository profiling and templates for GitHub Actions and GitLab CI.
- appsec-advisor-packaging-template — A template for packaging appsec-advisor as an internal Claude Code plugin with your organization's configuration.
- aiscb — The AI Secure Coding Baseline provides secure-coding rules for AI coding assistants such as Claude Code, GitHub Copilot, and Codex.
- tss-web — An open security requirements framework covering technical and organizational controls for developing and operating web applications and services. Discontinued: The content is no longer maintained or further developed.
Questions and bug reports are welcome in each project's issue tracker.