
oxo
Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

Modular security scanning orchestrator that combines specialized agents for vulnerability detection, reconnaissance, and fingerprinting across…

Let your AI go full send. Your home directory stays home.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Powershell-based bot framework

Easily create full virtual machines that are sandboxed for development or computer use models.

Benchmark for evaluating AI agents on real-world tasks including vulnerability resolution, code debugging, and protein assembly in containerized…

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

a static analysis tool for finding vulnerabilities in C/C++ source code

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

threatspec - continuous threat modeling, through code

Policy engine and EDR for AI agent fleets and developer workstations. Monitors tool calls, file access, network flows, and process execution with…

Lightweight, cross-platform process sandboxing powered by OpenAI Codex's runtime. Sandbox any command with file, network, and credential controls.

ClamAV antivirus scanning for Node.js — scan file uploads with a single function call. Zero dependencies. Typed Symbol verdicts. Local or…

A fast universal code security scanner, written in Rust. Batteries included: supports 14 languages, TUI for triage, secrets, post-quantum audits,…

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

Rootless container runtime and sandbox that launches kernel-enforced OCI images in milliseconds with no daemon, featuring resource profiles, seccomp…

RIPS - A static source code analyser for vulnerabilities in PHP scripts