
modelaudit
Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Security Scanner for Agent Skills

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Shell scripts to detect CVE-2024-3094 backdoor in liblzma5 across Kubernetes pods and Docker containers, with SBOM generation via Trivy for…

K8S and Docker Vulnerability Check for CVE-2024-3094

A lightweight caching proxy for package registries.

Malicious package & supply-chain intelligence

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…

Protect against malicious open source packages 🤖

Protect against malicious code installed via npm, yarn, pnpm, npx, pnpx, pip, uv and poetry with Aikido Safe Chain. Free to use, no tokens required.

GitHub Action that scans ML model files for malicious code and security vulnerabilities

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…