
flar
Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

Pentester-focused Docker registry tool to enumerate and pull images

Integration of Clair and Docker Registry

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Peirates - Kubernetes Penetration Testing tool

Gorsair gives root access on remote docker containers that expose their APIs

The easiest, and most secure way to access and protect all of your infrastructure.

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

Go-based Kubernetes exploitation tool that scans for exposed ports and exploits cluster misconfigurations, including anonymous Kubelet RCE and etcd…

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…


CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Go-based proof-of-concept exploit for CVE-2023-5044 in ingress-nginx, enabling authenticated remote command execution by creating crafted Kubernetes…

Go proof-of-concept demonstrating CVE-2026-46595 in golang.org/x/crypto/ssh, using symbol inspection of stripped binaries and image scans to verify…