
codetotal
Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Detect exposed API keys on GitHub commits.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Passive recon & attack surface mapper — zero requests sent

A vulnerability scanner for container images and filesystems

A tool to scan Kubernetes cluster for risky permissions

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.