
xnLinkFinder
A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Find and redact secrets in AI coding agent histories (Claude Code, and more).

Tool for advanced mining for content on Github

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…