
claudleak
Hunt for AI coding artifacts containing secrets.

Hunt for AI coding artifacts containing secrets.

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Source code for the Binaries of OWASP WrongSecrets

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

A doggo that helps look for security issues in your repositories.

The vibe-coding security sentinel. Apache-2.0 agentic security toolkit for AI-assisted projects: 5 deterministic scouts + LLM Brain Layer (BYOK…

StepSecurity owned org for analyzing compromised packages

Managing GitHub Advanced Security (GHAS) Controls at Scale

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

GitHub Action that scans ML model files for malicious code and security vulnerabilities

Scan codebases and GCP projects for exposed API credentials


AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.