
titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

A vulnerability scanner for container images and filesystems

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Pluggable linting tool to prevent committing credential.

Protect against malicious open source packages 🤖

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Ghidra is a software reverse engineering (SRE) framework

Open-source secret scanner in Rust

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Django application that performs SAST and Malware Analysis for Android APKs

Kubernetes RBAC static analysis & visualisation tool