
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

safe execution paths for agents - zero trust, zero setup, zero latency.

A fork of JSONPath from http://goessner.net/articles/JsonPath/

Find, verify, and analyze leaked credentials

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.