
secretlint
Pluggable linting tool to prevent committing credential.

Pluggable linting tool to prevent committing credential.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A doggo that helps look for security issues in your repositories.

reverse engineering tool with a built-in MCP server: an AI can debug your binary, not just read it — breakpoints, stepping, memory, calling…

Open-source Android client for VirusTotal. Scan files, URLs, and installed apps against 70+ antivirus engines. View detailed reports with hashes,…

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…

Reverse engineering and pentesting for Android applications

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

Self-hosted AI workspace with agents, skills, and tools (Gmail, Calendar) that runs entirely on your own provider API keys (BYOK). Bring your own…

CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

Apache RAT (Release Audit Tool) Gradle Plugin

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.