
EuConform
EU AI Act Compliance Tool - Risk classification and bias testing

EU AI Act Compliance Tool - Risk classification and bias testing

Runtime behavioral analysis tool that sandboxes suspicious packages in Docker, traces syscalls with strace, maps process cascades into directed…

Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations

A tool for finding vulnerable libwebp(CVE-2023-4863)

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

Apache RAT (Release Audit Tool) Gradle Plugin

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

CLI tool to scan codebases for quantum-vulnerable cryptography

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks…

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

Simple tool for scanning entire directories for attempts of CVE-2021-44228

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation