
pkgxray
Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Vulnerable app with examples showing how to not use secrets

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Scan codebases and GCP projects for exposed API credentials

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

sprint encode (plan text) get enc password

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).