
Bountystrike-sh
Poor (rich?) man's bug bounty pipeline https://dubell.io

Poor (rich?) man's bug bounty pipeline https://dubell.io

Python script to scan Git repos for interesting strings

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

Python source code auditing and static analysis on a large scale

CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A collection of tools to perform searches on GitHub.

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Portable security rules for the action boundary of AI agents

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets