
octoscan
Octoscan is a static vulnerability scanner for GitHub action workflows.

Octoscan is a static vulnerability scanner for GitHub action workflows.

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Zed Attack Proxy Scripts for finding CVEs and Secrets.

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more


Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Model Context Protocol server for autonomous vulnerability discovery

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components. Scan npm/pnpm/yarn lockfiles, Docker images, SBOMs,…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…