
layerleak
layerleak the Docker Hub Secret Scanner

layerleak the Docker Hub Secret Scanner

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

A project security/vulnerability/risk scanning tool

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

deb/rpm repository for Trivy

harbor unauthorized detection

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

A Public Package Scanner for The Community

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Extracts all the chart lists from ChartMuseum

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

AI coding agents that can't exfiltrate secrets or merge their own PRs.

A terminal-based AWS Security Scanner with 102+ security checks across VPC, IAM, S3, CloudTrail, containers (ECS/EKS), and AI attack detection.…

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

Vulnerability Assessment Scanner with Report Generation