
pkgxray
Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Vulnerable app with examples showing how to not use secrets

AI runtime inventory: discover shadow AI, trace LLM calls

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Scan codebases and GCP projects for exposed API credentials

A service that analyzes docker images and scans for vulnerabilities

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

sprint encode (plan text) get enc password

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…

Static code analysis tool based on Elasticsearch

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks