
API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API

Checklist of the most important security countermeasures when designing, testing, and releasing your API

Security scanner for AI agents, MCP servers and agent skills.

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

A library for detecting known secrets across many web frameworks

Proper sandboxing for agentic coding and web browsing

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Runtime security for AI agents: discover agents, map their permissions, and enforce what they can do.

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

Open-source security audits for Supabase: a read-only MCP server, a CLI agent and a Claude Skill. Finds RLS misconfigurations, exposed keys and risky…

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…