
osv-scanner
Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Find, verify, and analyze leaked credentials

Bandit is a tool designed to find common security issues in Python code.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Snyk CLI scans and monitors your projects for security vulnerabilities.

find hardcoded strings from source code

A native APK and DEX decompiler written in Rust

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Community curated list of templates for the nuclei engine to find security vulnerabilities.

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

0-day malware detection for binaries, source & scripts (that doesn't suck)

Static analysis CLI that scans AI-generated code for vulnerabilities like SQL injection, unsafe reflection, and hardcoded secrets, with SARIF export…

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.