Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Supply Chain Security | Kitploit
Categories

Supply Chain Security

Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.

Kitploit recommended

Top tools

10 selected
osv-scanner preview#1

osv-scanner

GitHubgoogle/osv-scanner
10.8k7h 7m ago
trivy preview#2

trivy

GitHubaquasecurity/trivy
37.4k1 day ago
grype preview#3

grype

GitHubanchore/grype
12.7k5 days ago
syft preview#4

syft

GitHubanchore/syft
9.6k15h 34m ago
scorecard preview#5

scorecard

GitHubossf/scorecard
5.6k15 days ago
cosign preview#6

cosign

GitHubsigstore/cosign
6.2k5 days ago
in-toto preview#7

in-toto

GitHubin-toto/in-toto
1.0k27 days ago
python-tuf preview#8

python-tuf

GitHubtheupdateframework/python-tuf
1.7k2 days ago
securesystemslib preview#9

securesystemslib

GitHubsecure-systems-lab/securesystemslib
542 days ago
dependency-track preview#10

dependency-track

GitHubdependencytrack/dependency-track
4.1k21h 2m ago
NewestRelevanceMost popularRecently updated
778 results
skill-scanner preview

skill-scanner

GitHubcisco-ai-defense/skill-scanner

Security Scanner for Agent Skills

static-analysisvulnerability-scannersdynamic-analysis-sandboxing+9
2.4k2 days ago
skills preview

skills

GitHubtrailofbits/skills

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

static-analysisvulnerability-analysiscode-analysis+8
6.5k2 days ago
zizmor preview

zizmor

GitHubzizmorcore/zizmor

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

static-analysisvulnerability-analysiscode-analysis+5
6.0k2 days ago
dep-scan preview

dep-scan

GitHubowasp-dep-scan/dep-scan

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

vulnerability-scannerscontainer-securitydevsecops+1
1.3k2 days ago
aquaman preview

aquaman

GitHubtech4242/aquaman

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

authentication-authorizationpenetration-testingcloud-security+7
362 days ago
ship-safe preview

ship-safe

GitHubasamassekou10/ship-safe

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

cloud-infrastructure-securitystatic-analysiscontainer-security+8
7853 days ago
probo preview

probo

GitHubgetprobo/probo

Open source solutions for SOC2, GDPR, and ISO27001

defensive-toolscloud-securitydevsecops+3
1.4k3 days ago
melange preview

melange

GitHubchainguard-dev/melange

Compiles source code into auditable, signed APK packages using declarative pipelines for Wolfi/Alpine, with multi-architecture QEMU emulation and…

container-securitydevsecopsutilities-frameworks+1
6283 days ago
ai-ctf preview

ai-ctf

GitHubmubix/ai-ctf

Local AI Capture-the-Flag platform with guided lessons on prompt injection, tool-call abuse, and OSINT against six simulated chatbot personas.

osintinformation-gatheringweb-security+6
183 days ago
foxguard preview

foxguard

GitHub0sec-labs/foxguard

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

static-analysisvulnerability-scannersencryption-decryption-tools+8
2803 days ago
shim-review preview

shim-review

GitHubrhboot/shim-review

Reviews of shim

vulnerability-analysiscode-analysissupply-chain-security+3
893 days ago
hijagger preview

hijagger

GitHubfirefart/hijagger

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

osintreconnaissancevulnerability-scanners+3
3053 days ago
jit preview

jit

GitHubjitpass/jit

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

authentication-authorizationencryption-decryption-toolsconfiguration-auditing+3
1603 days ago
hol-guard preview

hol-guard

GitHubhashgraph-online/hol-guard

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

defensive-toolsstatic-analysisvulnerability-scanners+7
6343 days ago
fad-checker preview

fad-checker

GitHub9pings/fad-checker

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

defensive-toolsstatic-analysisvulnerability-scanners+6
14 days ago
keyhog preview

keyhog

GitHubsanthreal/keyhog

Open-source secret scanner in Rust

static-analysisvulnerability-scannerscontainer-security+8
884 days ago
awesome-ai-security preview

awesome-ai-security

GitHubottosulin/awesome-ai-security

A collection of awesome resources related AI security

vulnerability-scannerspenetration-testingprivacy+6
1.4k4 days ago
async-http-client-check preview

async-http-client-check

GitHubxiaoqimikko/async-http-client-check

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

defensive-toolsstatic-analysisvulnerability-scanners+4
4 days ago
Previous1…345…44Next