Skip to content
View DSHCorrectover's full-sized avatar

Block or report DSHCorrectover

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
.github/profile/README.md

DSHCorrectover

Open-source security & provenance tooling from CorrectoverAI Reliability™. Every repository below ships evidence that is independently verifiable: signed receipts and Sigstore Rekor transparency-log anchors, no account needed to check.

🔏 Code provenance

  • code-birth-certificate — one GitHub Action: content-addressed manifest + Ed25519 receipt + Sigstore Rekor anchor (+ optional Zenodo DOI). Publicly verifiable code birth certificate, zero tokens.

🛡️ Runtime security scanning

  • correctover-scan — security scanner for MCP servers & AI agents: hardcoded secrets, RCE, SSRF, missing auth, credential hijacking (OWASP AISVS); also scans published/minified JS bundles (npx correctover-scan).
  • correctover-scan-action — drop-in GitHub Action: scan MCP config in CI, SARIF output, fail builds on critical findings.

🧪 Standards & conformance

  • ccs-conformance-vectors — public, signed conformance test vectors for the CCS (Correctover Conformance Shape) agent runtime-verification spec; this repo anchors itself to Rekor on every push (2697248662).

npx correctover-scan · correctover.com · evidence infrastructure for the AI age

Popular repositories Loading

  1. agent-audit agent-audit Public

    Manual security audit service for AI agents and MCP integrations — semantic intent review of tool permissions, command injection, SSRF and credential-exposure paths, with a free 1-page audit summary.

    HTML 1 1

  2. ccs-conformance-vectors ccs-conformance-vectors Public

    Public conformance test vectors for CCS (Correctover Conformance Shape) — signed, tamper-evident receipt fixtures for verifying AI agent runtime security implementations.

    Python 1 1

  3. awesome-mcp-devtools awesome-mcp-devtools Public

    Forked from Epistates/awesome-mcp-devtools

    A curated list of 100+ Model Context Protocol (MCP) developer tools — SDKs for 15 languages, frameworks, inspectors, testing and security scanners, proxies, gateways, hosting, and templates for bui…

    1 1

  4. correctover-scan-action correctover-scan-action Public

    GitHub Action: scan MCP (Model Context Protocol) configuration files for credential leaks, SSRF and missing auth in CI — SARIF output, fails builds on critical findings.

    JavaScript 1 1

  5. ccs-mcp-server ccs-mcp-server Public

    CCS MCP Server — 7-dimension runtime verification receipts for agent tool calls. Public mirror (project home: correctover.com).

    JavaScript 1 1

  6. evidence-screenshots evidence-screenshots Public

    public evidence screenshots

    1 1