
envy
A terminal based tool for managing secrets with both tui and cli support

A terminal based tool for managing secrets with both tui and cli support

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Ed25519 signed receipts + Cedar policies for AI agents. Finance mandate gate (Legate), proof packs, 3 IETF Internet-Drafts. npx protect-mcp

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Secure, private AI agent operating system with local encrypted storage, OAuth/SSO authentication, policy-based access control, and extensible…

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

Code signing and transparency for containers and binaries

Authorization engine for context-aware access control with YAML policies, RBAC/ABAC support, check/plan APIs, and GitOps-friendly deployment.

Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.

Collaborative Passwords Manager

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

A reverse proxy like nginx, built on pingora, simple and efficient.