
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Pluggable linting tool to prevent committing credential.

CLI tool for analyzing Go package capabilities by tracing transitive calls to privileged standard library operations, enabling supply chain risk…

PHP Static Analysis Tool - discover bugs in your code without running it!

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Bandit is a tool designed to find common security issues in Python code.

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

Automatic SSTI detection tool with interactive interface

I have created AegisJava, a tool to fix (detect and mitigate) CVE-2025-30749.

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Pishi is a code coverage tool like kcov for macOS.

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…