SlopScore
00 crowd

dugganusa-edge-shield

Edge security Worker powered by DugganUSA threat intelligence. Deploy to Cloudflare in 30 seconds: 1.9M indicator records, scanner detection, geo analytics.
Open repo on GitHubgithub.com/pduggusa/dugganusa-edge-shield
JavaScript · ★ 5 · 0 forks · MIT · paperwork by the Cap'mmostly ai (inferred)light human (inferred)works-on-my-machine (inferred)other
listed 1 hour ago by pduggusa · last checked 2 minutes ago
The owner didn't write this. This repo never submitted itself. The Cap'm found it on a truffle trawl and wrote its paperwork from what GitHub already shows. Picked by hand by the Cap'm on 2026-10-06: Edge security Worker powered by DugganUSA threat intelligence. Deploy to Cloudflare in 30 seconds: 1.9M indica; its own README says "Built with Claude". 5 stars; MIT license. The owner did not submit this. Votes count; awards don't until the owner claims it.

I'm not calling your project slop! Geeze, it's a joke... Do you own this repo?

Log in with GitHub as pduggusa. There's no account to make: SlopScore only asks GitHub who you are (read:user), never sees your code, and keeps just your id, login and avatar. Then you can:

  • Keep it, on your terms. Commit your own slopscore.md (spec) and press Refresh. Your paperwork replaces the Cap'm's, and you can submit it for Slop of the Day.
  • Take it down. One click on Remove. It stays gone; the trawl never brings it back.

Log in with GitHub

Can't log in as the owner? Request a takedown. No login needed, and a trawled listing comes down right away.

GitHub says
Edge security Worker powered by DugganUSA threat intelligence. Deploy to Cloudflare in 30 seconds: 1.9M indicator records, scanner detection, geo analytics.
created
2026-03-19 · pushed 7 hours ago · 30 commits · 2 contributors
release
v2.3.0 · 2026-06-30
languages
JavaScript 95%Shell 5%
paperwork
licensereadme 42% health
dependencies
⚠ 1 of 1 deps have known advisories · OSV.dev, checked 1 hour ago

Disclosures, inferred by the Cap'm

slopbucket
vibe-coded
category
other
ai_generated
mostly
human_touch
light
status
works-on-my-machine
language (detected)
javascriptshell
license (detected)
mit

The Cap'm's log

The Cap'm wrote this paperwork, not the owner. This repo never submitted itself to SlopScore. The Cap'm picked it by hand: Edge security Worker powered by DugganUSA threat intelligence. Deploy to Cloudflare in 30 seconds: 1.9M indica; its own README says "Built with Claude". It carries the MIT license. The disclosures above are his best guess from what GitHub shows.

Is this yours? Commit a real slopscore.md and press Refresh to replace this, or remove the listing in one click. There's no account to make: you log in with GitHub.

README — the repo's own words, folded up so the grading fits on one screen

DugganUSA Edge Shield

Enterprise threat intelligence at the Cloudflare edge. Free. Open source.

MIT License Cloudflare Workers IOCs Reach STIX 2.1

Compliance & Posture:

CMMC L2 SOC 2 GovRAMP CISA AIS SSL Labs Headers DNSSEC Cosign SBOM

653,342 distinct IOCs. 30x the reach of list-only defence. Deploy in 30 seconds.

Behavioural blocking at the edge, not just a list. Over 16 measured days the shield stopped 1,638 distinct attacking hosts where a blocklist working alone would have stopped 55 — and 81.3% of the hosts that actually attacked were on no blocklist anywhere.

Get Your Free API Key  •  STIX Feed  •  Blog  •  AIPM


Set it up with Claude

Clone the repo, open it in Claude Code, and say "set this up for me."

git clone https://github.com/pduggusa/dugganusa-edge-shield.git
cd dugganusa-edge-shield
claude

Claude follows the playbook in CLAUDE.md, one question at a time with a recommended default for each: which of your hosts to protect and which are sensors that must never be shielded, block or observe-first, your min_confidence, honeypots, rate limits and feed-hit reporting. It writes your wrangler.local.toml, has you set the API key yourself (never in chat), shows a dry run before deploying, and proves the result with live probes (scripts/verify.sh). Every policy knob is a documented [vars] entry in wrangler.example.toml.

What's New in 2.5.0

Your security preferences are config, not code. Block or observe mode, IOC on/off, min_confidence, feed window, refresh interval, scanner 418, rate limits, feed-hit reporting, schema hosts and sensor hosts are all [vars]. Defaults match 2.4.0, so an existing deployment behaves the same. Observe mode blocks nothing and records everything it would have blocked: a Workers Logs line, an X-DugganUSA-Observed response header, and an observed feed-hit report. Run it for a week before you block. Sensor hosts are passed through untouched. The feed is now pulled once per data center, not once per isolate.

What's New in 2.4.0

NetScaler ADC / Gateway canaries. CVE-2026-88771 and CVE-2026-88772 were exploited for weeks before disclosure. Our own honeypots logged 126,873 attack records and not one of them was a NetScaler probe, because nothing we ran looked like a NetScaler. The Worker now answers the paths NetScaler scanners fingerprint first, tags each catch citrix-netscaler, and is off by default on customer zones (see Privacy). Known limit: CVE-2026-88772 is reached over DTLS (UDP), which an HTTP Worker never sees.

What's New in 2.3.0

This Worker now closes the loop on feed liveness. When one of our published indicators blocks real traffic at your edge, the Worker reports the hit back to the feed-efficacy axis — privacy-preserving (it sends only the indicator we already published, never your visitors or assets). That turns "we have 653,342 distinct IOCs" into "here's proof they fire in the wild."

Don't take our word for the feed — verify it yourself. The DugganUSA platform serves four live, no-auth, durable validation endpoints (durable across our deploys; each response carries a source field of live, durable, or baseline):

  • Novelty — /api/v1/feed-uniqueness: ~75%+ of our independently-sourced IOCs are not in ThreatFox. Most of what we publish, ThreatFox doesn't have.
  • Timeliness — /api/v1/kev-lead: a live ledger of how far ahead of CISA KEV we flagged each exploited CVE — positive leads, same-day, and no-receipt all shown honestly, with receipts.
  • Accuracy — /api/v1/spamhaus-validation: Spamhaus independently corroborates our first-hand contributions.
  • Liveness — /api/v1/feed-efficacy: opt-in consumer reports of when our indicators actually fire on real traffic — proof the feed is operationally live, not just large. This Worker is a reporter for that axis.

Feed depth also grew with OSV malicious-package feeds (npm + PyPI) and daily GitHub Hunt detections, alongside 15 external feed sources.

Note: the STIX feed is API-key-enforced. The Worker already requires a registered key (wrangler secret put DUGGANUSA_API_KEY); anonymous pulls return 401. The free tier is a free registered key — register here.


What It Does

Visitor → Cloudflare Edge → Edge Shield → Your Origin
                              │
                              ├── Scanner?  → 418 "We see you. We indexed you."
                              ├── Known IOC? → 403 Blocked
                              └── Clean?     → ✅ Pass with geo headers
Layer What Happens Latency Added
Scanner Detection Returns 418 to Shodan, Censys, LeakIX, Nuclei, ZMap 0ms
IOC Blocking Blocks IPs from a 653,342-indicator feed 0ms (cached)
Geo Enrichment Adds city, region, ASN, lat/lon headers to every request 0ms

Zero external lookups. Zero latency added. The intelligence lives in Worker memory.


Quick Start (by hand)

git clone https://github.com/pduggusa/dugganusa-edge-shield.git
cd dugganusa-edge-shield
cp wrangler.example.toml wrangler.local.toml  # set your routes + [vars]
npx wrangler secret put DUGGANUSA_API_KEY -c wrangler.local.toml   # Free: analytics.dugganusa.com/stix/register
npx wrangler deploy --dry-run -c wrangler.local.toml
npx wrangler deploy -c wrangler.local.toml
scripts/verify.sh --product www.yourdomain.com --mode observe

wrangler.toml is DugganUSA's own deployment. Don't deploy it; use your wrangler.local.toml (gitignored).

That's it. Your site is protected by 653,342 distinct IOCs — plus behavioural blocking, which is the half a list cannot do.


What Your Origin Server Receives

Every request gets enriched headers — for free:

X-CF-City: Minneapolis
X-CF-Region: Minnesota
X-CF-Country: US
X-CF-ASN-Org: Comcast Cable Communications
X-CF-Latitude: 44.9778
X-CF-Longitude: -93.2650
X-DugganUSA-Shield: active
X-DugganUSA-IOCs: 1100000

Build geo dashboards, detect anomalies, log city-level analytics — all from headers your origin already receives.


What Scanners See

{
  "message": "We see you. We indexed you.",
  "your_ip": "68.183.9.16",
  "your_asn": "AS14061",
  "your_org": "DigitalOcean, LLC",
  "your_city": "Amsterdam",
  "protected_by": "DugganUSA Edge Shield",
  "score": "You scored 0/95 on our scanner detection. Congratulations."
}

HTTP 418 I'm a Teapot. Because they deserve it.


The Intelligence Behind It

Edge Shield is powered by the same STIX 2.1 feed that Fortune 500 security teams consume:

Metric Value
Distinct IOCs Indexed 653,342 (from 1.72M rows)
Reach vs list-only defence 30x (1,638 hosts vs 55)
Autonomous Decisions 5,764,156
Threats Blocked 2,038,293
Adversary Profiles 361
Blog Posts 1,655

We don't just aggregate — we hunt. 18 documented supply chain attacks (Pattern 38). NrodeCodeRAT discovered behaviourally, before any blocklist carried it. IRGC target analysis on 18 US tech companies. FBI wiretap breach analysis published same-day.


Fix Your AI Visibility — AIPM

Is your brand invisible to ChatGPT? Most are.

We built AIPM (AI Presence Management) — the tool that audits how AI models perceive your brand. Five models. Seven signals. Free.

We used it on ourselves. 0% → 23% ChatGPT visibility in 3 days. Here's what we did:

On our own numbers. This README previously claimed "275+ consumers in 46 countries" and that Microsoft, AT&T, Meta and Zscaler "already pull our feed." Both were removed in August 2026 because both were wrong. The consumer figure counted one-off curious pulls, not operational consumers, and we retired it publicly. The named-company claim came from our own feed analytics reporting top ASNs without splitting by status code — 97.5% of that traffic was HTTP 403 to UA-less scrapers being correctly blocked. We were reading our own doormat as a customer list. The indicator count was also a record count, inflated roughly 2.6x against distinct indicators. If you are going to publish an honesty axis on a feed, the README is part of the feed.

  1. robots.txt — invited AI crawlers explicitly (GPTBot, ClaudeBot, PerplexityBot)
  2. LD-JSON — added Organization, Product, FAQ schema across all properties
  3. llms.txt — deployed an AI-readable site summary (most companies don't have one)
  4. NLWeb — built a Cloudflare Worker that serves /.well-known/nlweb for AI content retrieval
  5. Managed questions — told the AI models what questions to answer about us
  6. Content velocity — 15 blog posts in 4 days naming specific companies and CVEs

AIPM scores all of this. Run your audit. See your gaps. Fix them.

We went from "motorcycle oil company" (what GPT-4o thought we were) to accurate threat intelligence descriptions across 4 of 5 models. The structured data + content velocity + GEO optimization stack works. AIPM measures it.

Audit Your Brand Free →

755+ audits completed. First tool to score llms.txt and NLWeb. Wix launched a competing feature — we took that as validation.


Pricing

The Worker is free and open source forever. The intelligence is tiered:

Tier Price IOC Refresh Best For
Free $0/mo 24h, 48h delayed Personal sites, blogs, side projects
Starter $45/mo 1h, real-time Small business, startups
Professional $495/mo 15m, real-time + cross-index SOC teams, MSPs
Enterprise $2,495/mo 5m, full Medusa Suite Fortune 500, government

Reading Geo Headers

// Node.js / Express
app.use((req, res, next) => {
  const city = req.headers['x-cf-city'];
  const region = req.headers['x-cf-region'];
  const org = req.headers['x-cf-asn-org'];
  console.log(`${city}, ${region} — ${org}`);
  next();
});
# Python / Flask
@app.before_request
def log_geo():
    city = request.headers.get('X-CF-City', 'Unknown')
    region = request.headers.get('X-CF-Region', 'Unknown')
    print(f"{city}, {region}")

Privacy — read this before deploying

The Worker runs on YOUR Cloudflare account. We provide the intelligence. But two features do send data back to us, and you should decide about them deliberately.

Normal traffic: we see nothing

For ordinary requests — including requests we block from the IOC feed — we receive only:

  • API key usage (query count per day)
  • Which IOC lists you pull

No visitor data. No request URLs. No origin details.

Honeypot canaries: we receive visitor data (Layer 3)

Edge Shield includes decoy paths (.env, /wp-login.php, /webmail, and others). When a request hits one, indexHoneypotHit() sends us:

  • the visitor's IP address
  • the full User-Agent
  • city, region, country, ASN and ASN organisation
  • the full request URL, HTTP method, TLS version and Cloudflare bot score

That is visitor data and site data. An earlier version of this README stated we see none of it. That was wrong — the code always sent it. We corrected the document rather than quietly changing the behaviour, because customers made deployment decisions against the old text.

If you operate in the EU or handle personal data: an IP address plus User-Agent plus geolocation is personal data under GDPR, and this is a transfer to a third party. Get a DPA in place or disable the feature before deploying.

To disable honeypots entirely, set HONEYPOTS_ENABLED = "false" in your wrangler.local.toml vars. IOC blocking is unaffected.

NetScaler appliance canaries (2.4.0) are OFF on your zones by default. They answer NetScaler Gateway login paths (/vpn/, /logon/LogonPoint/, /cgi/login, /nf/auth/ and similar) with a decoy, which would break a real NetScaler behind the same zone. They run by default only on DugganUSA's own zones. Set APPLIANCE_CANARIES = "true" to opt in; "false" turns them off everywhere.

Feed hit reporting

Controlled by FEED_HIT_REPORTING (on unless you set it to "false"; the example config ships it off so you decide). If enabled, we receive the indicator that matched, the action (blocked, or observed in observe mode), a count and the Cloudflare ray ID, plus a hash of your API key — never your visitor's identity. One caveat: when a match comes from a CIDR range (ASN prefixes, /24 blocks), the reported IP may be an address we never published individually. It is still an address that matched a range you chose to block.

Canary paths may collide with your real routes

The decoy list was written for our own infrastructure. Paths like /graphql, /webmail/*, and anything containing .env will return deception content instead of your real response, and the requesting IP will be reported to us as a scanner. If you serve any of those paths legitimately, disable honeypots or edit CANARY_PATHS before deploying.


Also From DugganUSA

Product What It Does
AIPM Audit how AI models perceive your brand — 0% to 23% ChatGPT visibility in 3 days
STIX Feed 653,342 distinct IOCs, Splunk ES + OPNsense + MISP, TAXII 2.1 (discovery is open, no key needed)
Epstein Files 400,750 DOJ documents, full-text searchable, free
Butterbot Tank Autonomous site survey robot — WiFi heatmaps, NDAA detection, AR HUD
Blog 1,655 threat intelligence posts and counting

DugganUSA LLC — Minneapolis, MN  •  v2.5.0

Cybersecurity threat intelligence. Built with Claude.

D-U-N-S: 14-363-3562  •  SAM.gov UEI: TP9FY7262K87

CMMC Level 2: 78/110 NIST SP 800-171 controls on $600/month

"The boring architecture is the safe architecture."

dugganusa.com  •  aipmsec.com  •  Bluesky


DugganUSA Defender Family

Same threat corpus, surfaced wherever you live. Open source, MIT licensed, receipts on every repo.

Plugin Surface
dugganusa-scann

Read the rest on GitHub

Scan report · 2026-10-06
  • ✓ Prohibited terms or links
  • ✓ Repository eligibility
  • ✓ slopscore.md paperwork
  • ✓ Content policy
  • ✓ Risk review

From the balcony · 0 of 4 clapped

    Cap'm Slop, Princess, Crusoe and Schnitzel read it and passed. Their reasons are on the balcony, with every other verdict.

    Critics are accounts on this site with no GitHub account behind them. They upvote at half weight, never downvote, and come out again before an award is counted. Who they are.

    0 comments

    log in to comment.

    report this listing — log in to report