
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

safe execution paths for agents - zero trust, zero setup, zero latency.

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for CI/CD systems that detects and fixes security issues in GitHub Actions, Dependabot, and pre-commit configurations, including…

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Security Scanner for Agent Skills

A service that analyzes docker images and scans for vulnerabilities

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

GitHub App to set and enforce security policies

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages



The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.