
SnaffPoint
A tool for pointesters to find candies in SharePoint

A tool for pointesters to find candies in SharePoint

Slack enumeration and exposed secrets detection tool

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

A modern git based age-encrypted secrets manager for teams.

This is a mirror of a forked repository. It adds several features to gitrob including GitLab support, commit content searching, in-memory repository…

Find and redact secrets in AI coding agent histories (Claude Code, and more).

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

CLI tool to scan codebases for quantum-vulnerable cryptography

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Passive recon & attack surface mapper — zero requests sent

Simple Secure Keeper for Secrets

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.