
git-secrets
Prevents you from committing secrets and credentials into git repositories

Prevents you from committing secrets and credentials into git repositories

An enterprise friendly way of detecting and preventing secrets in code.

A wrapper around grep, to help you grep for things

a guard that blocks catastrophic agent actions

Python source code auditing and static analysis on a large scale

Python script to scan Git repos for interesting strings

Octoscan is a static vulnerability scanner for GitHub action workflows.

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Regex-based scanner for detecting hard-coded credentials in codebases, designed for CI/CD integration with suppression comment support and low…

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…


StepSecurity owned org for analyzing compromised packages

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

Detailed analysis of CVE-2026-22038, a high-severity vulnerability in AutoGPT Stagehand blocks that logs API keys in plaintext, including root cause,…