
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@chain305/x-security
Advanced tools
x-security CLI — generate/validate/test/report/diff/init against multiple gateway targets
Compile, validate, test, and report on x-security policies in OpenAPI specs — deterministic, no LLM calls, no API keys.
npx @chain305/x-security --help
| Command | What it does |
|---|---|
xsecurity generate <spec> --target <t> | Compile an annotated OpenAPI spec into gateway config (kong, coraza, bunkerweb, openappsec, firewall, envoy) |
xsecurity validate <spec> --target kong --gateway <url|file> | Detect drift between the spec and a running/exported gateway config |
xsecurity test <spec> --target <t> | Closed-loop test: generate config, spin up Docker, send traffic, assert |
xsecurity verify <spec> --target <t> --gateway <addr> | Read-only post-deploy check that the gateway loaded the emitted artifacts |
xsecurity report <spec> | OWASP API Top 10 coverage and annotation reports |
xsecurity diff <old> <new> --target <t> | Diff the generated config for two spec versions |
xsecurity init <spec> | Add empty x-security blocks to operations missing them |
xsecurity migrate <spec> --from 0.4 --to 0.5 | Rewrite a spec between schema versions |
Run xsecurity <command> --help for full flags.
x-security test)Apache-2.0
FAQs
x-security CLI — generate/validate/test/report/diff/init against multiple gateway targets
The npm package @chain305/x-security receives a total of 9 weekly downloads. As such, @chain305/x-security popularity was classified as not popular.
We found that @chain305/x-security demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.