#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…
Offline single-binary web app that ingests CycloneDX, SPDX and syft SBOMs, runs an ensemble of CVE scanners, enriches findings with EPSS, CISA-KEV…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

Local AI Capture-the-Flag platform with guided lessons on prompt injection, tool-call abuse, and OSINT against six simulated chatbot personas.

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

A macOS app to scan Xcode project files for possible security issues.

Pure-JS drop-in for [email protected] without the vulnerable native binding (CVE-2025-3194)

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to…

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

A service that analyzes docker images and scans for vulnerabilities

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure


Identify hardcoded secrets in static structured text

A software supply chain framework powered by Nix.

Scanners for Jar files that may be vulnerable to CVE-2021-44228