SecFathy/xss-specialist
KEV-gated continual-learning XSS specialist with execution-authoritative browser verification
About the project
Research prototype for XSS discovery: an offline study on specializing a small LLM via KEV-gated continual learning plus a live authorized assessment system where findings are confirmed only by execution in a headless browser.
Useful for
- Assess an authorized web target for XSS with headless-browser confirmation
- Run the local /v1/systemone server for typed XSS decisions
- Convert benchmark data into decision-model training format
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 73 stars so far today, about 90 expected by the end of the day.
- The spike has held for 2 days in a row — not a one-off blip.
- The repository is 1 day old and already has 97 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet.
- Top new repositories this week: #169.
- About 8 forks a day — people are taking the code.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 97
- Today
- 73 · ≈ 90 by evening
- Forks
- 8
- Issues and pull requests
- 0
- Watchers
- 0
- Language
- Python
- Latest release
- xss-decision-0.8b-kev-specialist-v2 · September 28, 2026
- Created
- September 27, 2026
- Last push
- September 28, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 28, 2026Top new repositories this week: #169
More in this category
-
5.1
JoasASantos/Offensive-Security-AI-Models
A curated list of open-weight uncensored LLMs fine-tuned for cybersecurity tasks such as red teaming, penetration testing and security research. Each entry lists base model, size, context, VRAM and uncensoring method.
-
5.0
dagowda/notRDP
A Havoc C2 plugin that creates a hidden alternate Windows desktop, streams it to a browser viewer, and forwards mouse and keyboard input while staying invisible to the target user.
-
5.0
angusdevgo/Seep-Reverse-Lab
Agent-native reverse engineering workbench for binaries and CWE-602 client-side authorization auditing: unifies Radare2, JADX, Apktool, Frida and IDA via 23 MCP tools with automatic task routing.
-
4.8
derv82/wifit3
Cross-platform USB Wi-Fi auditor in Python: scans networks, captures WPA handshakes and PMKIDs, attacks WPS and WEP via its own userland drivers without aircrack-ng.
-
4.6
TwoSevenOneT/InjectSetConsole
Proof of Concept for Windows process code injection via a named pipe, without using VirtualAllocEx or WriteProcessMemory. Demonstrates an EDR evasion technique for security researchers.
-
4.4
newliver666/apk-reverse
An Agent Skill for Android APK reverse engineering: unpacking, ad removal, dex patching, repacking, and runtime/server analysis. Loaded by an agent (Claude Code, Codex) while it works.