
mcp-xray
Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.


Open Source Vulnerability Management Platform

OpenSSF Scorecard - Security health metrics for Open Source

Open source vulnerability DB and triage service.

Open Source Cloud Native Application Protection Platform (CNAPP)

An open source threat modeling tool from OWASP

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

Open source solutions for SOC2, GDPR, and ISO27001

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

Protect against malicious open source packages 🤖

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

ProjectDiscovery's Open Source Tool Manager

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…