
go-mal-pkgs
A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

A security tool to detect malicious Go packages by verifying checksums in go.sum against the original source code

GNU IFUNC is the real culprit behind CVE-2024-3094

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

A lightweight caching proxy for package registries.

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…