
ContextHound
Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

AI-powered security co-pilot that catches vulnerabilities as you code. Real-time security scanning, educational explanations, and auto fixes for…

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

GitHub Action that scans ML model files for malicious code and security vulnerabilities

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Scans GitHub workflows and logs for indicators of CVE-2025-30066, detecting malicious actions and exposed secrets using Checkmarx 2ms integration.


A project security/vulnerability/risk scanning tool

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Octoscan is a static vulnerability scanner for GitHub action workflows.

Open-source secret scanner in Rust

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Detect exposed API keys on GitHub commits.


Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…