
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Find, verify, and analyze leaked credentials

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Static Analyzer for Starknet smart contracts

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Run iOS apps without actually installing them!

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

safe execution paths for agents - zero trust, zero setup, zero latency.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Reverse engineering assistant that uses a locally running LLM to aid with pseudocode analysis.

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

A demonstration of CVE-2022-42889 (text4shell) remote code execution vulnerability

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Fast and accurate AI powered file content types detection

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…