
agent-governance-toolkit
Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.


Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…


A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

The Secure Coding Framework


SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

The dependency-check repository has moved: