
mcp-server-attestation
Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

A project security/vulnerability/risk scanning tool

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Zero shot vulnerability discovery using LLMs

Extract URLs, paths, secrets, and other interesting bits from JavaScript

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Pluggable linting tool to prevent committing credential.

Security-focused static analysis for the Phoenix Framework

Obfuscate a python code 2.x and 3.x

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

A Chrome extension static analysis tool to help aide in security reviews.

Static analysis tool that scans source code for hardcoded secrets, API keys, and credentials using semantic understanding of code context.

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

Java bytecode analyzer customizable via JSON rules

A lightweight security auditor and sandbox for shell scripts. Oversight combines a Static Analysis engine (Rust) with Dynamic Enforcement (Linux…