Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

16 Commits

Repository files navigation

+ ███████╗███████╗██████╗ ██████╗+ ╚══███╔╝██╔════╝██╔══██╗██╔═══██╗+ ███╔╝ █████╗ ██████╔╝██║ ██║+ ███╔╝ ██╔══╝ ██╔══██╗██║ ██║+ ███████╗███████╗██║ ██║╚██████╔╝+ ╚══════╝╚══════╝╚═╝ ╚═╝ ╚═════╝+ ██╗███╗ ██╗████████╗███████╗██╗+ ██║████╗ ██║╚══██╔══╝██╔════╝██║+ ██║██╔██╗ ██║ ██║ █████╗ ██║+ ██║██║╚██╗██║ ██║ ██╔══╝ ██║+ ██║██║ ╚████║ ██║ ███████╗███████╗+ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚══════╝╚══════╝+

Every codebase has a confession. Most people never ask it the right question.


This is not a security audit. Security audits tell you what is broken.

This tells you why it was always going to break.

The ghost is never in the line that fails. The ghost is in the assumption that was never questioned.


The 20 Subjects

Ranked by strategic value, architectural complexity, and the gap between reputation and substrate.

Security Tools

We turned the forensic lens on the forensic tools.

RepoStarsReport
projectdiscovery/nuclei27,725→ reports/security/nuclei.md
rapid7/metasploit-framework37,835→ reports/security/metasploit-framework.md
nmap/nmap12,636→ reports/security/nmap.md
sqlmapproject/sqlmap36,985→ reports/security/sqlmap.md
NationalSecurityAgency/ghidra66,563→ reports/security/ghidra.md

AI / ML Infrastructure

The frameworks training the world's models. What trains the framework?

RepoStarsReport
pytorch/pytorch98,800→ reports/ai-ml/pytorch.md
tensorflow/tensorflow194,457→ reports/ai-ml/tensorflow.md
huggingface/transformers158,691→ reports/ai-ml/transformers.md
langchain-ai/langchain132,000→ reports/ai-ml/langchain.md
vllm-project/vllm75,004→ reports/ai-ml/vllm.md

Infrastructure

The substrate beneath the cloud. Invisible until it isn't.

RepoStarsReport
kubernetes/kubernetes121,487→ reports/infrastructure/kubernetes.md
hashicorp/terraform48,000→ reports/infrastructure/terraform.md
grafana/grafana73,000→ reports/infrastructure/grafana.md
elastic/elasticsearch76,405→ reports/infrastructure/elasticsearch.md

NPM / Web

The dependencies nobody audits because everyone depends on them.

RepoStarsReport
facebook/react220,000→ reports/npm-web/react.md
axios/axios105,000→ reports/npm-web/axios.md
vercel/next.js138,582→ reports/npm-web/nextjs.md

Trending / AI Agents

The repos shipping fastest. Speed and rigor are inversely correlated — until they aren't.

RepoStarsReport
ollama/ollama166,779→ reports/trending/ollama.md
supabase/supabase100,075→ reports/trending/supabase.md
Significant-Gravitas/AutoGPT183,064→ reports/trending/autogpt.md

Report Anatomy

 ██████╗ ██╗ █████╗ ███████╗███████╗██╗███████╗██╗███████╗██████╗
██╔════╝ ██║ ██╔══██╗██╔════╝██╔════╝██║██╔════╝██║██╔════╝██╔══██╗
██║ ██║ ███████║███████╗███████╗██║█████╗ ██║█████╗ ██║ ██║
██║ ██║ ██╔══██║╚════██║╚════██║██║██╔══╝ ██║██╔══╝ ██║ ██║
╚██████╗ ███████╗██║ ██║███████║███████║██║██║ ██║███████╗██████╔╝
╚═════╝ ╚══════╝╚═╝ ╚═╝╚══════╝╚══════╝╚═╝╚═╝ ╚═╝╚══════╝╚═════╝

The report structure is not published.

The methodology is not disclosed.

What runs beneath the surface has been deliberately kept off the record — not to obscure the findings, but to protect the integrity of the analysis. A known instrument can be played.

What we can say:

█████ ███████ ██████ ████████ ██ ████ ████████ ██████ ███████ ████ ██████████.
████████ ██ ███ ████████ ████ ██████ ███████ ██████████ ████ ██████ ███ ████.
██████ ███ ████ ███ █████████ ██████████ ████ ███████████ ████████ ████ █████.
███ ████████ ████ ██████ ████ ███ ██████ ████████████ ████ ██████████ ███████.

Every report opens with the verdict. One sentence. The complete payload.

Everything after it is evidence.

The ghost is never in the line that fails. It is in the assumption that was never questioned.


What you are reading is approximately 1% of the full report.

The published version is a heavily redacted surface — architectural observations, structural patterns, and the ghost-in-the-commits made safe for public disclosure. Zero-days, exploit chains, active attack paths, and credential archaeology are withheld for security reasons and delivered exclusively to verified owners via commissioned reports.

Reports are generated using large language models as the synthesis layer. The raw signals feeding that synthesis are not disclosed.

The redaction is not a limitation. It is the product.


Submit a Repo for Analysis

The 20 subjects above were chosen by us. The next 80 are already targeted.

But the pipeline is not closed. If you have a target in mind — a codebase you depend on, one you're about to acquire, one you built and need an honest verdict on — submit it.

FreeCommission
Repo typePublic onlyPublic or private
Report depthBasic — verdict, git archaeology, structural vulnerabilitiesFull — zero-days, exploit chains, complete attack path mapping
Who gets itPublished here, publiclyDelivered privately to you only
DeliveryWithin 72 hours of approvalWithin 48 hours of payment
PriceFree$10,000 USD
VettingAll requests reviewed — not every submission acceptedOwnership verified before payment is requested

Request a free analysis

Commission a full report ($10,000)

Nominate a target for the pipeline

Challenge a published verdict


What This Is Not

Not a bug bounty operation. Not a responsible disclosure repo. Not a list of CVE IDs.

A CVE gets patched. An architectural assumption gets inherited by the next generation of the codebase.

The patch fixes the symptom. We're measuring the condition.


Zero Intelligence

Independent research on intelligence as a structural property of any system.

Not a domain. Not a platform. The substrate beneath both.

zero-intelligence


Reports are live documents. Each analysis reflects the state of the repository at time of scan. Git history is permanent — the ghost never leaves.

Releases

Packages

Used by

Contributors