
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Filesystem scanner for Log4Shell (CVE-2021-44228) and related CVEs. Detects vulnerable JAR files via hash matching and class presence. Runs…

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Pluggable linting tool to prevent committing credential.

Lan Tian's NixOS Configuration

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

GitHub Action that scans ML model files for malicious code and security vulnerabilities

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…