
lightweight_static_analysis
Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Clickbait. The CVE is AI slop.

PHP Static Analysis Tool - discover bugs in your code without running it!

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Bandit is a tool designed to find common security issues in Python code.

An extensible multilanguage static code analyzer.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

grep rough audit - source code auditing tool

This skill helps Claude write secure code and prevent common vulnerabilities.

VisualCodeGrepper - Code security scanning tool.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Curated Ghidra scripts to automate reverse engineering and vulnerability analysis: locate insecure functions, extract decompiler pseudocode, fix…

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)