
Agentic-Bug-Hunter
AI-powered bug bounty hunting toolkit that works with or without subscription.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

A security scanner for your LLM agentic workflows

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Linting tool for CloudFormation templates

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

The Secure Coding Framework

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

An extensible multilanguage static code analyzer.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Static analysis rule pack for detecting security vulnerabilities, dangerous code patterns, and configuration issues across many languages; integrates…

PHP Static Analysis Tool - discover bugs in your code without running it!