Turn a proven HTTP exploit into a permanent, deterministic security regression test.
Install
Install the GitHub Action from Marketplace, download the archive for your platform below and verify it with SHA256SUMS, or install the CLI with Go:
go install github.com/pazent/exploitspec/cmd/exploitspec@v0.1.0What ships in v0.1.0
- RED → GREEN → STABLE calibration against vulnerable and fixed baselines
- isolated multi-actor HTTP sessions, captures, JSONPath, regex, and header assertions
- conservative cURL import that redacts secrets without executing the command
- safe redirects, response limits, explicit host authorization, and metadata-IP blocking
- text, JSON, and JUnit reports with deterministic exit codes
- a free composite GitHub Action and versioned JSON Schema
- Linux, macOS, and Windows archives for AMD64 and ARM64
ExploitSpec is Apache-2.0, local-first, account-free, telemetry-free, and has no paid tier.
- GitHub Marketplace
- Passing GitHub Actions template
- BOLA/IDOR case study
- Quick start
- Specification
- Security model
- Launch announcement
Every security bug deserves a regression test.