
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Go static analysis tool that checks for security issues using an AST.

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

grep rough audit - source code auditing tool

This skill helps Claude write secure code and prevent common vulnerabilities.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

a static analysis tool for finding vulnerabilities in C/C++ source code

Static code analysis tool based on Elasticsearch