
keyFinder
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

Passive recon & attack surface mapper — zero requests sent


A tool for secrets management, encryption as a service, and privileged access management

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Simple and flexible tool for managing secrets

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

A vulnerability scanner for container images and filesystems

Incredibly fast crawler designed for OSINT.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Snyk CLI scans and monitors your projects for security vulnerabilities.

OpenSSF Scorecard - Security health metrics for Open Source