
pqaudit
Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

how to look for Leaked Credentials !

Vulnerability Assessment Scanner with Report Generation

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Finding exposed secrets and personal data in GitLab

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

Extract URLs, paths, secrets, and other interesting bits from JavaScript

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

A tool to capture all the git secrets by leveraging multiple open source git searching tools

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

List of regex for scraping secret API keys and juicy information.

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.

Automated OSINT tool that scans SwaggerHub API documentation to discover exposed secrets, credentials, and sensitive information using regex-based…