
sentrymcp
A static + runtime security scanner for MCP (Model Context Protocol) servers

A static + runtime security scanner for MCP (Model Context Protocol) servers
Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536,…

🛡️ One-command scanner for CVE-2026-45321 — TanStack npm supply-chain attack

Hustle Plugin <= 7.8.3 contains hardcoded HubSpot API credentials in inc/providers/hubspot/hustle-hubspot-api.php

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

Checks Djangos /static/staticfiles.json for exposed creds using nuclei

A library for detecting known secrets across many web frameworks

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Anteater - CI/CD Gate Check Framework

The dependency-check repository has moved:

Web-based Source Code Vulnerability Scanner

automated web assets enumeration & scanning [DEPRECATED]

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

Notes about attacking Jenkins servers

BeHat Configuration file leaking