
httpx-action
HTTP Web Server probing

HTTP Web Server probing

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

End to End testing of Web, API, Cloud, Events and Security

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

The easiest, and most secure way to access and protect all of your infrastructure.

Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and…

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.