
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Open source vulnerability DB and triage service.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Automated vulnerability data aggregator that collects advisories from NVD, OSV, Alpine, Red Hat, and 20+ other sources into a unified parsable format…

The DevSecOps toolset for REST APIs

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Rust-powered HTTP Request Smuggling Scanner.

Malicious package & supply-chain intelligence

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

⚡️ Multiple target ZAP Scanning

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Faraday Agent Dispatcher launches any security tools and send results to Faradaysec Platform.

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…