
threatmap
IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

credential isolation for AI agents. Agents never see real API keys - structural guarantee, not policy.

layerleak the Docker Hub Secret Scanner

TrustedRouter.com repo for secure LLM proxying

Enforce least-privilege delegation for AI agents with signed, scoped credentials. Grant sub-agents narrow capabilities and resources, verify actions…

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Open source tooling to stop ICS phishing (malicious calendar invites)

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

PoC for CVE-2021-43557

An S3 account ID enumeration and bucket discovery tool

A small, auditable, terminating, deterministic micro-policy engine

Security gateway for MCP servers with per-tool policy enforcement, Ed25519-signed audit receipts, and shadow-mode logging. Supports Cedar, OPA, and…