Skip to content

SnailSploit/SnailSploit

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

7 Commits
Β 
Β 
Β 
Β 

Repository files navigation

SnailSploit Banner

SnailSploit

GenAI Security Researcher Β· AI Red Teamer Β· Offensive Security Writer

Website The Jailbreak Chef LinkedIn


I'm Kai Aizen β€” independent security researcher focused on adversarial AI, LLM red teaming, and the intersection of social engineering and prompt injection. I build frameworks and tooling for structured AI safety testing.

Creator of AATMF Β· Author of Adversarial Minds Β· 8 CVEs Β· Linux kernel contributor Β· Hakin9 Contributing Author


πŸ”΄ Frameworks & Tooling

Project Description
AATMF v3.1 Adversarial AI Threat Modeling Framework β€” 20 tactics, ~240 techniques. Maps to OWASP LLM Top-10, NIST AI RMF, MITRE ATLAS. AATMF
AATMF Red Teaming Toolkit Python CLI for systematic LLM safety testing β€” three-layer eval pipeline, defense fingerprinting, decay tracking, attack chain planning. NEW
LLM Red Teamer's Playbook Diagnostic methodology for bypassing LLM defense layers β€” input filters β†’ alignment β†’ identity β†’ output β†’ agentic trust.

πŸ§ͺ Experiments & PoCs

Project Description
ChatGPT-DNS-Exfill DNS exfiltration via ChatGPT Canvas β€” rendered content triggers DNS lookups without HTTP requests.
chatgpt-rce-dns DNS exfiltration and Python Pickle RCE attack chains in AI code execution sandboxes.

πŸ› οΈ Offensive Tools

Tool Description
Burp MCP Toolkit MCP security analysis for Burp Suite β€” prompt injection and tool poisoning testing via Model Context Protocol.
SnailHunter AI-powered bug bounty automation β€” LLM analysis combined with traditional security scanning.
KubeRoast Red-team Kubernetes misconfiguration and attack-path scanner.
Xposure Autonomous credential intelligence platform for attack surface recon.
SnailSploit Recon Chrome MV3 extension for passive recon and bug bounty automation.
ZenFlood Low-bandwidth stress testing β€” modernized Slowloris.
Claude-Red Curated offensive security skills library for the Claude skills system.
SnailObfuscator Structurally-aware code obfuscation engine.

πŸ›‘οΈ CVEs

CVE Target Type Severity
CVE-2026-3288 ingress-nginx Config Injection β†’ RCE High (8.8)
CVE-2026-31899 CairoSVG Exponential DoS β€” recursive amplification High (7.5)
CVE-2025-9776 CatFolders SQL Injection via CSV Import Medium (6.5)
CVE-2025-12163 OmniPress Stored XSS Medium (6.4)
CVE-2025-11171 Chartify Missing Authentication Medium (5.3)
CVE-2025-11174 Document Library Lite Unauth Info Disclosure Medium (5.3)
CVE-2025-12030 ACF to REST API IDOR Medium (4.3)
CVE-2026-1208 Welcart CSRF to Settings Update Medium (4.3)

πŸ”“ Security Advisories

Advisory Target Type Severity
GHSA-j425-whc4-4jgc OpenClaw (309k⭐) system.run env override RCE β€” allowlist bypass via GIT_SSH_COMMAND, editor hooks, GIT_CONFIG_* Medium (6.3)

🐧 Kernel Research

Finding Component Type Status
io_uring/zcrx Race Condition Linux kernel io_uring/zcrx Race Condition β†’ Double-Free β†’ OOB Write βœ… Upstream, backported to v6.18.16

SnailSploit

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors