
openclarity
OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

Finding secrets in kernel and user memory

Collection of Azure Tools to Pull down for Attacking an Environment + quick tips and other useful information

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Git hook-based secret scanner that detects tokens, passwords, and private keys in outgoing changesets, preventing sensitive data from being committed…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

how to look for Leaked Credentials !

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

A lightweight mcp to prevent poisoning CVE (CVE-2025-54136), researchers hijacking Claude Code/Copilot/Gemini via prompt injection, and hundreds of…

Harden your package manager configs against supply chain attacks.

Deploy self-hosted AI coding agents (OpenClaw, Claude Code, Codex) into your AWS account with CloudFormation, IAM profiles, and sandbox isolation for…

Automated dependency security layer for AI coding assistants that audits packages for CVEs, typosquats, abandonment, version-age issues, and hash…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Model Context Protocol server for autonomous vulnerability discovery

Anticipator is an open-source threat detection platform for multi-agent AI systems.

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)