
git-alerts
Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Declarative KVM/QEMU VM orchestration tool using YAML compose files. Manages multi-VM stacks with cloud-init, SSH, PCI passthrough, and image…

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

All-in-one tool for managing vulnerability reports from AppSec pipelines

OWASP Kubernetes security and compliance tool [WIP]

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Lightweight CLI tool that runs AI coding agents inside isolated Bubblewrap sandboxes with strict filesystem, network, and credential isolation to…

CLI tool for the Horizon3.ai API

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Manage OpenClaw in your team (Enterprise) by providing it compute infrastructure, tool integration, Authentication and security primitives

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Apache RAT (Release Audit Tool) Gradle Plugin

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production