#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Community-owned database of security advisories for Python packages on PyPI, providing structured vulnerability data in OSV format for integration…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

eBPF-powered runtime security sensor for CI/CD pipelines. Detects supply-chain attacks, logs process ancestry and file access, and provides forensic…

Pure-JS drop-in for [email protected] without the vulnerable native binding (CVE-2025-3194)

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

Supply-chain Levels for Software Artifacts

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

Source code for the Binaries of OWASP WrongSecrets

Using code search to help fix/mitigate log4j CVE-2021-44228

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.