
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

A vulnerability scanner for container images and filesystems

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Proper sandboxing for agentic coding and web browsing

layerleak the Docker Hub Secret Scanner

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

deb/rpm repository for Trivy

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

GitLab CI component for Trivy scanning

Hardened dasel v3.3.1 package and image built via Melange and apko. Patching CVE-2026-33320.

:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:

Extracts all the chart lists from ChartMuseum