
trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

Protect against malicious open source packages 🤖

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

a guard that blocks catastrophic agent actions

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Open-source secret scanner in Rust

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…


Open-source, cross-platform, multi-purpose security auditing tool

A project security/vulnerability/risk scanning tool

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…