


Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

An open source threat modeling tool from OWASP

A GitHub Action invoking the Gemini CLI.


Intentionally vulnerable Terraform infrastructure for learning cloud misconfiguration detection and DevSecOps practices across AWS, Azure, and GCP.

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Purple Team Exercise Framework

The Open-Source AWS Cyber Range

Documenting your Threat Models with HCL

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

threatspec - continuous threat modeling, through code