#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…
patches for SNYK-JS-JQUERY-174006, CVE-2019-11358, CVE-2019-5428

Open source vulnerability DB and triage service.


Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

Source code for the Binaries of OWASP WrongSecrets

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Proof of concept for CVE-2024-24590

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Software Component Verification Standard (SCVS)

GitHub App to set and enforce security policies

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

POC of CVE-2021-42574 for solidity and solc compiler

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

Local AI Capture-the-Flag platform with guided lessons on prompt injection, tool-call abuse, and OSINT against six simulated chatbot personas.