
sast-scan
Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

A simple file-based scanner to look for potential AWS access and secret keys in files

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

Maven-based demonstration of CVE-2023-33246 mitigation for Apache RocketMQ, featuring attack testing and enhanced parameter validation to prevent…


The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Find, verify, and analyze leaked credentials

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

secure multiplexed execution paths for agents - zero trust, zero setup, zero latency.

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Security Governance for Agentic AI

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

This skill helps Claude write secure code and prevent common vulnerabilities.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.