Skip to content
View lirantal's full-sized avatar
💟
AI Security, Hacking Agents, MCPs and Socially Engineering LLMs
💟
AI Security, Hacking Agents, MCPs and Socially Engineering LLMs

Organizations

@meanjs @nodejs @snyk @jsheroes @verdaccio @TheSecureDeveloper @snyk-labs @create-node @community-snyk

Block or report lirantal

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
lirantal/README.md

Hi, I'm Liran 👋

I created a series of comprehensive vulnerable code deep-dive training books on Secure Coding in Node.js to help developers master Node.js security with hands-on vulnerability review and remediation walkthroughs

Node.js Secure Coding: Defending Against Command Injection Vulnerabilities
Node.js Secure Coding: Defending Against Command Injection Vulnerabilities
Node.js Secure Coding: Prevention and Exploitation of Path Traversal Vulnerabilities
Node.js Secure Coding: Prevention and Exploitation of Path Traversal Vulnerabilities
Mitigate and Weaponize Code Injection Vulnerabilities
Node.js Secure Coding: Mitigate and Weaponize Code Injection Vulnerabilities

Software Engineer · Web Security Activist · Author

A GitHub Star, world-wide recognized for championing open source software and actively working within communities to inspire and lift other humans. Liran also received the OpenJS Foundation's Pathfinder for Security for his work on Node.js security. A JavaScript & Node.js software developer, building web applications and command-line tools. A web security activist , engaging in security research, software supply chain security, and regular contributor and project lead to OWASP Foundation projects. An avid member of the Node.js Foundation ecosystem security working group, dedicated to advancing Node.js security awareness and skill-set in the open source community. Developer Advocate at Snyk.

Twitter


Awarded:

Web Security Activism

Blog & other resources

Published Author

Essential Node.js Security
Essential Node.js Security

Liran Tal
Web Security: Learning HTTP Security Headers
Web Security: Learning HTTP Security Headers

Liran Tal
O'Reilly Serverless Security
O'Reilly Serverless Security

Guy Podjarny, Liran Tal
State of Open Source Security 2019
Snyk's State of Open Source Security 2019

Liran Tal

Pinned Loading

  1. npq npq Public

    safely install npm packages by auditing them pre-install stage

    JavaScript 1.2k 28

  2. ls-mcp ls-mcp Public

    List MCP Server configurations in your system used by AI applications like Cursor, Claude Desktop, VS Code and others

    TypeScript 55 4

  3. awesome-mcp-best-practices awesome-mcp-best-practices Public

    Build Awesome MCPs with Awesome Best Practices for MCP Servers and MCP Clients

    38

  4. agent-rules agent-rules Public

    Rules and instructions for agentic coding tools like Cursor, Claude CLI, Gemini CLI, Qodo, Cline and more

    TypeScript 21

  5. mcp-server-nodejs-api-docs mcp-server-nodejs-api-docs Public

    MCP Server for Node.js API documentation

    TypeScript 7 1

  6. llm-ai-security-demo llm-ai-security-demo Public

    JavaScript 2 11