
DongTai
Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

System utility that identifies and restarts daemons using outdated libraries after package upgrades to maintain security. Supports containers and…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Easily create full virtual machines that are sandboxed for development or computer use models.

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

a guard that blocks catastrophic agent actions

Python client for Batfish, a network configuration analysis tool that validates security, reliability, and compliance by modeling network behavior…

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

JIT-based userspace Linux kernel that runs containers natively on Apple Silicon macOS without a VM. Drop-in Docker Engine API replacement with…

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…