
aws-vault
A vault for securely storing and accessing AWS credentials in development environments

A vault for securely storing and accessing AWS credentials in development environments

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web…

A static + runtime security scanner for MCP (Model Context Protocol) servers

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

how to look for Leaked Credentials !

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Check rclone config files for insecure passwords

FARO - Document Sensitivity Detector

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

A small Rust CLI that strips secrets from your clipboard on demand.

Open-source secret scanner in Rust

Harden your package manager configs against supply chain attacks.


Detection & remediation toolkit for the Miasma / Shai-Hulud worm and CVE-2026-35603 (AI-agent/IDE config injection)

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).