
raptor
Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

safe execution paths for agents - zero trust, zero setup, zero latency.

Find, verify, and analyze leaked credentials

Operator to streamline renovate executions in Kubernetes

Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.

The wolfSSL library is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3 and DTLS…

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Find and redact secrets in AI coding agent histories (Claude Code, and more).

Powerful protection for AI agents - Open-source security and cost tracking for AI applications

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

GitHub App to set and enforce security policies

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.