
pip-audit
Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

a guard that blocks catastrophic agent actions

Validates leaked API tokens and keys using customizable JSON-based signature checks. Designed for pentesters and bug hunters to determine the impact…

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

Find and redact secrets in AI coding agent histories (Claude Code, and more).

A simple file-based scanner to look for potential AWS access and secret keys in files

Extracts secrets (passwords, API keys, tokens) from WARC web archives using Gitleaks rules. Supports HTTP, S3, local files, and compressed archives…

Hunt for AI coding artifacts containing secrets.

Web-based dashboard to visualize, filter, and analyze secrets discovered by TruffleHog, with batch verification, export, and session management for…

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Passive recon & attack surface mapper — zero requests sent

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

This is a mirror of a forked repository. It adds several features to gitrob including GitLab support, commit content searching, in-memory repository…