
wheelaudit
Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

Open-source, cross-platform, multi-purpose security auditing tool

Validate environment variable usage in codebase

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Read-only scanner for what lets a repository run code in a coding agent (Claude Code, Codex, Cursor, Copilot): git settings, hooks, and committed MCP…

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536,…

Scan codebases and GCP projects for exposed API credentials

Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis.…

Identify hardcoded secrets in static structured text

Open source compliance tool for development platforms.

Prevents you from committing secrets and credentials into git repositories

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

a guard that blocks catastrophic agent actions

Octoscan is a static vulnerability scanner for GitHub action workflows.

Open-source secret scanner in Rust

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Vulnerability Assessment and Auditing Framework for all the Crypto Implementations.

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…