
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Find, verify, and analyze leaked credentials

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Octoscan is a static vulnerability scanner for GitHub action workflows.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Main repo for hosting release binaries

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

safe execution paths for agents - zero trust, zero setup, zero latency.

nodejsscan is a static security code scanner for Node.js applications.

Protect against malicious open source packages 🤖

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

find hardcoded strings from source code

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.