
enjarify
Translates Dalvik bytecode (DEX/APK) to equivalent Java bytecode, enabling Java analysis tools to process Android applications with high correctness…

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Android and Java bytecode viewer

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Python library for local LLM-powered security analysis with Ghidra binary analysis, C/C++ vulnerability scanning, and MCP tool integration for…

Identify hardcoded secrets in static structured text

A tool to hunt for credentials in github wild AKA git*hunt

Pishi is a code coverage tool like kcov for macOS.

Go static analysis tool that checks for security issues using an AST.

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

CLI tool that scans codebases for high-entropy lines to detect potential secrets, with customizable file extension and top-N filtering.

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Static analysis tool that scans Dockerfiles for insecure commands and configuration issues, providing actionable security notifications to harden…

CLI tool to scan codebases for quantum-vulnerable cryptography

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…