
static-code-analysis-helper
Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

A security scanner for your LLM agentic workflows

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Bandit is a tool designed to find common security issues in Python code.

C++ python bytecode disassembler and decompiler

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Python Command-Line Ghidra Decompiler

AST-based Python code transformation & deobfuscation framework

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Specialized reasoning LLM for source-code vulnerability detection in C/C++ and Python, with dataset construction, SFT/DPO training, and…

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…