
grype
A vulnerability scanner for container images and filesystems

A vulnerability scanner for container images and filesystems

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

how to look for Leaked Credentials !

Android security insights in full spectrum.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

a guard that blocks catastrophic agent actions

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

Harden your package manager configs against supply chain attacks.

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Proper sandboxing for agentic coding and web browsing

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…