
aura
Project Aura: Security auditing and code introspection

GitHub Action that scans ML model files for malicious code and security vulnerabilities


Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Python source code auditing and static analysis on a large scale

A Public Package Scanner for The Community

Identify hardcoded secrets in static structured text

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

An enterprise friendly way of detecting and preventing secrets in code.

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Mobile Helper Framework (mhf) is a tool that automates the process of identifying the framework/technology used to create a mobile application.…

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Source code for the Binaries of OWASP WrongSecrets

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…