

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams


Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…

sprint encode (plan text) get enc password

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Detect exposed API keys on GitHub commits.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Mobile Application Vulnerability Detection

A Public Package Scanner for The Community

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

BeHat Configuration file leaking

Appspec YML and YAML leaks

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574