
Apkx-Hunter
C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

OWASP Secure Agent Playbook Project

Source code for the Binaries of OWASP WrongSecrets

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

The dependency-check repository has moved:

Vulnerable app with examples showing how to not use secrets

Zed Attack Proxy Scripts for finding CVEs and Secrets.

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.