
horusec
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

A project security/vulnerability/risk scanning tool

Pluggable linting tool to prevent committing credential.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Tool for advanced mining for content on Github

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

OWASP Secure Agent Playbook Project

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

Project Aura: Security auditing and code introspection

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

Open Source Cloud Native Application Protection Platform (CNAPP)

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform