
ci-supplychain-guard
Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Project Aura: Security auditing and code introspection

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Security Scanner for Agent Skills

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Python source code auditing and static analysis on a large scale

Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

Malicious package & supply-chain intelligence

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.