
GiveMeSecrets
Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Strip credential-like content from free-form strings before they reach logs or telemetry. Part of the phpboyscout Go toolkit. ·…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Extracts all the chart lists from ChartMuseum

Verified tool registry manager. Manages developer toolchains from git-based registries.

Aurea is an open-source, AI-powered platform that secures infrastructure-as-code (IaC) across Terraform, Kubernetes, Docker, and Ansible. It…

This skill helps Claude write secure code and prevent common vulnerabilities.

An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…

Passive recon & attack surface mapper — zero requests sent

Mobile Application Vulnerability Detection

Managing GitHub Advanced Security (GHAS) Controls at Scale