
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Open Source Cloud Native Application Protection Platform (CNAPP)

Tool for advanced mining for content on Github

Pluggable linting tool to prevent committing credential.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

A project security/vulnerability/risk scanning tool

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

OWASP Secure Agent Playbook Project

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs,…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

A Git-native dependency admission controller. Evaluates trust signals on every dependency change and blocks commits or builds when packages fail your…