
Veritensor
The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

All-in-one tool for managing vulnerability reports from AppSec pipelines

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.


AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

MCP server for Slither static analysis of Solidity smart contracts

Detect and patch vulnerable Apache Commons Text in Java JAR/WAR artifacts; fingerprint classes and scan bytecode for CVE-2022-42889 (Text4Shell) call…

A ConfuserEx2 deobfuscator with support for anti tamper, compressor, constants, control flow, and resource recovery.

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

A Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x "JNDI LDAP" vulnerability.