
cve-lite-on-pi
Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).
The dependency-check repository has moved:

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Vulnerable app with examples showing how to not use secrets

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Zed Attack Proxy Scripts for finding CVEs and Secrets.

OWASP Secure Agent Playbook Project

Source code for the Binaries of OWASP WrongSecrets

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis