Show HN: We wrote forensic intelligence reports on 20 open-source codebases

DhruvKumarJha1 pts0 comments

GitHub - zero-intelligence/zero-intel: Every codebase has a confession. Most people never ask it the right question. · GitHub

/" data-turbo-transient="true" />

Skip to content

Search or jump to...

Search code, repositories, users, issues, pull requests...

-->

Search

Clear

Search syntax tips

Provide feedback

--><br>We read every piece of feedback, and take your input very seriously.

Include my email address so I can be contacted

Cancel

Submit feedback

Saved searches

Use saved searches to filter your results more quickly

-->

Name

Query

To see all available qualifiers, see our documentation.

Cancel

Create saved search

Sign in

/;ref_cta:Sign up;ref_loc:header logged out"}"<br>Sign up

Appearance settings

Resetting focus

You signed in with another tab or window. Reload to refresh your session.<br>You signed out in another tab or window. Reload to refresh your session.<br>You switched accounts on another tab or window. Reload to refresh your session.

Dismiss alert

{{ message }}

zero-intelligence

zero-intel

Public

Notifications<br>You must be signed in to change notification settings

Fork

Star

main

BranchesTags

Go to file

CodeOpen more actions menu

Folders and files<br>NameNameLast commit message<br>Last commit date<br>Latest commit

History<br>16 Commits<br>16 Commits

.github/ISSUE_TEMPLATE

.github/ISSUE_TEMPLATE

reports

reports

README.md

README.md

TARGETS.md

TARGETS.md

View all files

Repository files navigation

+ ███████╗███████╗██████╗ ██████╗<br>+ ╚══███╔╝██╔════╝██╔══██╗██╔═══██╗<br>+ ███╔╝ █████╗ ██████╔╝██║ ██║<br>+ ███╔╝ ██╔══╝ ██╔══██╗██║ ██║<br>+ ███████╗███████╗██║ ██║╚██████╔╝<br>+ ╚══════╝╚══════╝╚═╝ ╚═╝ ╚═════╝<br>+ ██╗███╗ ██╗████████╗███████╗██╗<br>+ ██║████╗ ██║╚══██╔══╝██╔════╝██║<br>+ ██║██╔██╗ ██║ ██║ █████╗ ██║<br>+ ██║██║╚██╗██║ ██║ ██╔══╝ ██║<br>+ ██║██║ ╚████║ ██║ ███████╗███████╗<br>+ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚══════╝╚══════╝

Every codebase has a confession. Most people never ask it the right question.

This is not a security audit. Security audits tell you what is broken.

This tells you why it was always going to break.

The ghost is never in the line that fails. The ghost is in the assumption that was never questioned.

The 20 Subjects

Ranked by strategic value, architectural complexity, and the gap between reputation and substrate.

Security Tools

We turned the forensic lens on the forensic tools.

Repo<br>Stars<br>Report

projectdiscovery/nuclei<br>27,725<br>→ reports/security/nuclei.md

rapid7/metasploit-framework<br>37,835<br>→ reports/security/metasploit-framework.md

nmap/nmap<br>12,636<br>→ reports/security/nmap.md

sqlmapproject/sqlmap<br>36,985<br>→ reports/security/sqlmap.md

NationalSecurityAgency/ghidra<br>66,563<br>→ reports/security/ghidra.md

AI / ML Infrastructure

The frameworks training the world's models. What trains the framework?

Repo<br>Stars<br>Report

pytorch/pytorch<br>98,800<br>→ reports/ai-ml/pytorch.md

tensorflow/tensorflow<br>194,457<br>→ reports/ai-ml/tensorflow.md

huggingface/transformers<br>158,691<br>→ reports/ai-ml/transformers.md

langchain-ai/langchain<br>132,000<br>→ reports/ai-ml/langchain.md

vllm-project/vllm<br>75,004<br>→ reports/ai-ml/vllm.md

Infrastructure

The substrate beneath the cloud. Invisible until it isn't.

Repo<br>Stars<br>Report

kubernetes/kubernetes<br>121,487<br>→ reports/infrastructure/kubernetes.md

hashicorp/terraform<br>48,000<br>→ reports/infrastructure/terraform.md

grafana/grafana<br>73,000<br>→ reports/infrastructure/grafana.md

elastic/elasticsearch<br>76,405<br>→ reports/infrastructure/elasticsearch.md

NPM / Web

The dependencies nobody audits because everyone depends on them.

Repo<br>Stars<br>Report

facebook/react<br>220,000<br>→ reports/npm-web/react.md

axios/axios<br>105,000<br>→ reports/npm-web/axios.md

vercel/next.js<br>138,582<br>→ reports/npm-web/nextjs.md

Trending / AI Agents

The repos shipping fastest. Speed and rigor are inversely correlated — until they aren't.

Repo<br>Stars<br>Report

ollama/ollama<br>166,779<br>→ reports/trending/ollama.md

supabase/supabase<br>100,075<br>→ reports/trending/supabase.md

Significant-Gravitas/AutoGPT<br>183,064<br>→ reports/trending/autogpt.md

Report Anatomy

██████╗ ██╗ █████╗ ███████╗███████╗██╗███████╗██╗███████╗██████╗<br>██╔════╝ ██║ ██╔══██╗██╔════╝██╔════╝██║██╔════╝██║██╔════╝██╔══██╗<br>██║ ██║ ███████║███████╗███████╗██║█████╗ ██║█████╗ ██║ ██║<br>██║ ██║ ██╔══██║╚════██║╚════██║██║██╔══╝ ██║██╔══╝ ██║ ██║<br>╚██████╗ ███████╗██║ ██║███████║███████║██║██║ ██║███████╗██████╔╝<br>╚═════╝ ╚══════╝╚═╝ ╚═╝╚══════╝╚══════╝╚═╝╚═╝ ╚═╝╚══════╝╚═════╝

The report structure is not published.

The methodology is not disclosed.

What runs beneath the surface has been deliberately kept off the record — not to obscure the findings, but to protect the integrity of the analysis. A known instrument can be played.

What we can say:

█████ ███████ ██████ ████████ ██ ████ ████████ ██████ ███████ ████ ██████████.<br>████████ ██ ███ ████████ ████ ██████ ███████ ██████████ ████ ██████ ███ ████.<br>██████ ███ ████ ███ █████████ ██████████ ████ ███████████ ████████ ████ █████.<br>███ ████████ ████ ██████ ████ ███ ██████ ████████████ ████ ██████████ ███████.

Every...

reports security report infrastructure search repo

Related Articles