
packj
Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

Find, verify, and analyze leaked credentials

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize

Scalable fuzzing infrastructure with coverage-guided engines (libFuzzer, AFL, Honggfuzz), automated crash deduplication, bug filing, and regression…

Security Scanner for Agent Skills

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Security Governance for Agentic AI

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

Easily create full virtual machines that are sandboxed for development or computer use models.

Model Context Protocol server for autonomous vulnerability discovery

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.