#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…
The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS…

Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build…

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

A collection of awesome resources related AI security

Transparent file encryption in git

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Open source vulnerability DB and triage service.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord,…

Security scanner for AI agents, MCP servers and agent skills.

Supply-chain Levels for Software Artifacts

Security Scanner for Agent Skills

Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.

A dead simple tool to sign files and verify digital signatures.

Python reference implementation of The Update Framework (TUF)