
wrongsecrets-binaries
Source code for the Binaries of OWASP WrongSecrets

Source code for the Binaries of OWASP WrongSecrets

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

OWASP Secure Agent Playbook Project

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

The dependency-check repository has moved:

Vulnerable app with examples showing how to not use secrets

Zed Attack Proxy Scripts for finding CVEs and Secrets.

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Vulnerability Assessment Scanner with Report Generation