
Sighthound
Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security


JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

Security scanner for AI agents, MCP servers and agent skills.

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Community curated list of templates for the nuclei engine to find security vulnerabilities.

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

XMachOViewer is a Mach-O viewer for Windows, Linux and MacOS

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Semantic graph-based version control for AI-written code. Tracks entities and relations instead of file diffs, enabling blast radius analysis, shadow…

OWASP Certified Secure-Software Developer