
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

This Repositories contains list of One Liners with Descriptions and Installation requirements

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Credential and sensitive-data exposure triage for file shares

Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. ·…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

Hunting for passwords with deep learning


A collection oneliner scripts for bug bounty

List of regex for scraping secret API keys and juicy information.

A tool for pointesters to find candies in SharePoint

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org