
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

A security focused static analysis tool for Android and Java applications.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

safe execution paths for agents - zero trust, zero setup, zero latency.

A fork of JSONPath from http://goessner.net/articles/JsonPath/

Find, verify, and analyze leaked credentials

Pluggable linting tool to prevent committing credential.

The system of record for AI-written software. A persistent graph of entities, relationships, changes, and provenance, so humans and AI agents see…


A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.