
horusec
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

OWASP Secure Agent Playbook Project

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

Project Aura: Security auditing and code introspection

A project security/vulnerability/risk scanning tool

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

agent runtime security - zero trust, zero setup, zero latency.

Open Source Cloud Native Application Protection Platform (CNAPP)

Tool for advanced mining for content on Github

Pluggable linting tool to prevent committing credential.

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…