
ElectricEye
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting…

Audits Python environments, requirements files and dependency trees for known security vulnerabilities, and can automatically fix them

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

A simple file-based scanner to look for potential AWS access and secret keys in files

A modern git based age-encrypted secrets manager for teams.

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.


CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

A project security/vulnerability/risk scanning tool

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.