
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Security-focused static analysis for the Phoenix Framework

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Obfuscate a python code 2.x and 3.x

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

A Chrome extension static analysis tool to help aide in security reviews.

A tool that automatically creates fuzzing harnesses based on a library

find hardcoded strings from source code

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Pishi is a code coverage tool like kcov for macOS.

NOVA - Claude Code Protection System against prompt injection attacks

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Java bytecode analyzer customizable via JSON rules

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…