
npq
safely install npm packages by auditing them pre-install stage

safely install npm packages by auditing them pre-install stage

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

Pluggable linting tool to prevent committing credential.

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

Dependency analysis and optimization toolkit for modern JavaScript and TypeScript codebases. Enforce dependency graph hygiene and remove unused code…

A desktop workbench for writing, validating, compiling, and testing YARA rules.

MCP server integrating IDA Pro with AI agents, featuring a stateless gateway for multi-session management, a relational SQL query engine for binary…

Configuration Extractors for Malware

Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

A doggo that helps look for security issues in your repositories.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…


Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation and modern…

Static analysis of malicious Python code

A static + runtime security scanner for MCP (Model Context Protocol) servers