Skip to content
View WRG-11's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report WRG-11

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
WRG-11/README.md

🛡️ WinstonRedGuard · WRG-11

Pseudonymous solo research lab for AI/LLM security, detection engineering & OSINT tooling

Working artifacts, not promises. The five featured project repositories are MIT-licensed.

featured projects are MIT-licensed sigma rules

Python 3.12 · Sigma · MCP · OSINT · MITRE ATT&CK · Claude Code


Solo researcher working on AI/LLM security, detection engineering, and OSINT tooling. I publish small, security-focused open-source artifacts I actually use: vulnerable-by-design labs, a client-side secret scanner, Sigma detection content, OSINT trust envelopes, and a deny-by-default desktop-automation MCP server. Several core tools are standard-library-only. Bug reports and detection rules occasionally land upstream.

🧪 Security labs & research

mcp-objauthz-lab   updated

Vulnerable-by-design MCP server for learning object-level / cross-tenant authorization (BOLA/IDOR) bugs, paired with a hunt checklist and CI that keeps the vulnerable-fixture set honest.

ai-security-toolkit   updated

Offensive & defensive AI/LLM security tools, labs, and CTF write-ups. Zero-dependency Python.

🔍 Scanners

devguard-scan   updated   ·   ▶ live demo

100% client-side secret scanner. Paste code or drop files; nothing leaves your browser (zero upload).

📡 Detection / Sigma

wrg-sigma-rules   updated

294 Sigma detection rules across 16 ATT&CK tactic categories, none marked `stable` — sigma's `status:` field used literally rather than aspirationally. Ships 3 MCP tools + 3 Claude Code skills.

🧭 OSINT & research

osint-trust-envelope   updated

Per-source epistemic ceilings for OSINT results: honest verified / inferred / heuristic / unverified envelopes. Zero-dependency Python.

🖥️ Desktop automation (MCP)

desktop-automation-mcp   Apache-2.0   updated

Deny-by-default, per-action-gated Windows window MCP server. Every capability (observe, click, type, close, drag) is a separately granted permission, and every effect is re-verified against the live target (identity, focus, occlusion) right before it runs. It hands the client pixels and window-relative coordinates, never on-screen text, so screen content cannot be mistaken for instructions. UIA-less canvas apps are supported through versioned, hash-verified coordinate profiles.


🛡 Security advisories

Credited reporter on published GitHub Security Advisories:

  • Pelican: application API mounts ACL-scope bypass, CWE-862/863 (GHSA-43h8-3896-wqv5)
  • Pelican: Filament suspend-all / unsuspend-all missing authorization (GHSA-4wxv-r46p-w2f9)
  • Jexactyl: free-billing flow missing ownership check, CWE-862 (GHSA-9xwv-p7r5-5h5p)
  • OneUptime: incoming-call-number resend-verification-code missing ownership check — the sibling channel the CVE-2026-30959 fix sweep left uncovered, CWE-862 (GHSA-wc96-jm46-37hh)

Vendor security acknowledgement:

  • zn: high-severity control-plane authorization gap on policy and consensus handlers, where non-admin tenant keys could modify policy or consensus state through missing function-level checks (SEC-2026-01, credited on the usezn.com Security Hall of Fame)

🔗 Upstream detections

Detection templates merged into projectdiscovery/nuclei-templates:

  • CVE-2026-26190 Milvus, unauthenticated metrics port (#16333)
  • CVE-2026-25527 changedetection.io ≤ 0.52.9 (#16346)
  • CVE-2026-33476 SiYuan ≤ v3.6.1 (#16335)
  • CVE-2026-31831 Tautulli ≤ 2.16.1, unauthenticated path traversal (#16345)

0 of 294 sigma rules marked stable · no open CodeQL alerts across 5 featured repos (checked 2026-09-20) · MIT-licensed featured projects · standard-library-first where it makes sense

Pinned Loading

  1. devguard-scan devguard-scan Public

    100% client-side secret scanner - a dependency-free, zero-upload browser port of the wrg-devguard scan engine. Paste code or drop files; nothing leaves your browser. Also ships a Node CLI and a Git…

    JavaScript

  2. wrg-sigma-rules wrg-sigma-rules Public

    Sigma rules for ransomware, threat actors and vulnerabilities disclosed in AI/LLM apps and MCP servers, with multi-backend conversion and an MCP server for Claude Code, Codex and Cursor. CI-pinned …

    Python 2

  3. ai-security-toolkit ai-security-toolkit Public

    Offensive & defensive AI/LLM security tools, labs, CTF writeups, and research. Zero-dependency Python toolkit.

    Python 1

  4. mcp-objauthz-lab mcp-objauthz-lab Public

    Vulnerable-by-design MCP server for learning object-level / cross-tenant authorization (BOLA/IDOR) bugs, plus Semgrep rules that find the same shapes in JavaScript/TypeScript, Python, Go, Rust, Jav…

    JavaScript

  5. osint-trust-envelope osint-trust-envelope Public

    Per-source epistemic ceilings for OSINT results: wrap any lookup in an honest trust envelope (verified/inferred/heuristic/unverified). Zero-dependency Python.

    Python

  6. desktop-automation-mcp desktop-automation-mcp Public

    Deny-by-default, per-action-gated Windows window MCP server

    Python