
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Find and redact secrets in AI coding agent histories (Claude Code, and more).

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

A modern git based age-encrypted secrets manager for teams.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

Verified tool registry manager. Manages developer toolchains from git-based registries.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets


Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.