
nono
secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

Pluggable linting tool to prevent committing credential.

Security Governance for Agentic AI

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Performing security tests inside your CI

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

MCP server for structured STRIDE-based threat modeling with automatic code validation, business context analysis, and comprehensive report generation…

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Open-source secret scanner in Rust

OWASP Secure Agent Playbook Project

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI