ExploitSpec

ExploitSpec

Turn proven HTTP exploits into permanent regression tests

3 followers

ExploitSpec is a free, local-first CLI and GitHub Action that turns a confirmed HTTP security finding into a deterministic regression test. Define isolated actors, capture dynamic values, assert the security boundary, and calibrate RED → GREEN → STABLE. v0.2 adds bounded, conservatively redacted HAR import without replaying traffic. Plain YAML, Apache-2.0, Homebrew, no account, telemetry, or hosted service. It is not a scanner: you supply the proven finding.

ExploitSpec makers

Here are the founders, developers, designers and product people who worked on ExploitSpec