
cve-lite-on-pi
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

OWASP Kubernetes security and compliance tool [WIP]

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

An open source threat modeling tool from OWASP

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

Rust-powered HTTP Request Smuggling Scanner.