
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Run iOS apps without actually installing them!

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…


Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Rule-based static and dynamic analysis tool that identifies capabilities in PE, ELF, .NET, and shellcode files, mapping them to MITRE ATT&CK…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Security scanner for AI agents, MCP servers and agent skills.

Security Scanner for Agent Skills

More than a ReClass port to the .NET platform.

Rule-based Android malware scoring engine that analyzes APKs using static and dynamic analysis to detect vulnerabilities, identify malware families,…

A lightweight dynamic instrumentation library