#1Dependency scanning, SBOM generation, package integrity, and supply chain risk tools.
Kitploit recommended

Smart Tree: not just a tree, a philosophy. A context-aware, AI-crafted replacement for 20+ tools with MEM8 quantum compression, semantic search,…
Harden your package manager configs against supply chain attacks.

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

A Python library to parse, validate and create SPDX documents.

Curated repository of documented firmware supply chain attacks, featuring IoCs, detection tools, and references to help defenders understand and…

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Malicious package & supply-chain intelligence

IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and…

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

TPM Genie is an I2C bus interposer for discrete Trusted Platform Modules

BloodHound OpenGraph collector for GitHub that maps organization structure, permissions, and cross-cloud attack paths into a navigable graph for…

Safely install NPM packages

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Curated dataset of cloud middleware agents installed by AWS, Azure, and GCP, documenting past vulnerabilities, privileges, and attack-surface risks…