
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Octoscan is a static vulnerability scanner for GitHub action workflows.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Source code for the Binaries of OWASP WrongSecrets

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Security Scanner for Agent Skills

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

A doggo that helps look for security issues in your repositories.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Checks projects for compromised packages, suspicious files, and import statements.

CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

OWASP Secure Agent Playbook Project