
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Application Security Verification Standard

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

CVE-2022-22947

OWASP Secure Agent Playbook Project

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs


détection des attaques sql/xss sur API web avec IA

批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947