
packj
Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Tool to check for dependency confusion vulnerabilities in multiple package management systems

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…


Identify hardcoded secrets in static structured text

An agent to hotpatch the log4j RCE from CVE-2021-44228.

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Static analysis of malicious Python code

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

The Anti-Virus for AI Artifacts & RAG Firewall. A static analysis tool scanning Models and Notebooks for RCE, Datasets and RAG docs for Data…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations