
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Find, verify, and analyze leaked credentials

Octoscan is a static vulnerability scanner for GitHub action workflows.

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

safe execution paths for agents - zero trust, zero setup, zero latency.

find hardcoded strings from source code

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Prevents you from committing secrets and credentials into git repositories

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

OpenSSF Scorecard - Security health metrics for Open Source

An enterprise friendly way of detecting and preventing secrets in code.