
medusa
AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE (CVE-2023-34039)

CVE-2023-34039

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

OWASP Secure Agent Playbook Project

Open-source secret scanner in Rust


Professional Service scripts to aid in the identification of affected Java applications in TeamServer


Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.



100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI