
hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at…

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Aurea is an open-source, AI-powered platform that secures infrastructure-as-code (IaC) across Terraform, Kubernetes, Docker, and Ansible. It…

Software Component Verification Standard (SCVS)

CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Open-source secret scanner in Rust

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Prompt-injection guardrail for LLM applications. Compact model that outperforms larger open-source guards. No regex, no signatures. Demo:…

EU AI Act Compliance Tool - Risk classification and bias testing

DepAlert is an open-source security gate for your CI/CD pipeline. It analyzes SBOMs against malware intelligence data and quickly tells you whether…

Minimal CVE Hardened container image collection

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Semantic graph-based version control for AI-written code. Tracks entities and relations instead of file diffs, enabling blast radius analysis, shadow…

Powerful protection for AI agents - Open-source security and cost tracking for AI applications