#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Reviews of shim

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Tool to check for dependency confusion vulnerabilities in multiple package management systems

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

Python source code auditing and static analysis on a large scale

Scans Software Bill of Materials (SBOMs) for security vulnerabilities

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

A lightweight caching proxy for package registries.

Proper sandboxing for agentic coding and web browsing

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

An agent to hotpatch the log4j RCE from CVE-2021-44228.

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…