
SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Pluggable linting tool to prevent committing credential.

Model Context Protocol server for autonomous vulnerability discovery

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

A static + runtime security scanner for MCP (Model Context Protocol) servers

Open-source secret scanner in Rust

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

Ghidra is a software reverse engineering (SRE) framework

Protect against malicious open source packages 🤖

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Kubernetes RBAC static analysis & visualisation tool

A vulnerability scanner for container images and filesystems