#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Security scanner for AI agents, MCP servers and agent skills.
Minimal CVE Hardened container image collection

Software Supply Chain Security Platform

Snyk CLI scans and monitors your projects for security vulnerabilities.

The Most Comprehensive Docker Security Scanner

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…


A lightweight caching proxy for package registries.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Open source solutions for SOC2, GDPR, and ISO27001

Open source vulnerability DB and triage service.

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

Reviews of shim

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration