#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Vulnerability scanner written in Go which uses the data provided by https://osv.dev
Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

A vulnerability scanner for container images and filesystems

Snyk CLI scans and monitors your projects for security vulnerabilities.

GameLoop update MITM

Aggregates vulnerability data from multiple databases into CycloneDX SBOMs, generating deduplicated VEX, HTML, and GitLab-compatible reports for…

Find, verify, and analyze leaked credentials

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Malicious package & supply-chain intelligence

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…