
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

threatspec - continuous threat modeling, through code

OpenSSF Scorecard - Security health metrics for Open Source

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Documenting your Threat Models with HCL

Distributed SIP honeypot that detects and shares fraud data on VoIP attacks. Collects bad actor IPs and phone numbers via peer-to-peer network, with…

Proxy server that wraps MCP servers with behavioral profiling, security scanning, risk gating, and safe execution. Detects prompt injection,…

AI-powered reactive website defense system that detects attacks, analyzes them, and autonomously patches source code in real-time using LLM agents.

OWASP Secure Agent Playbook Project

B2B software vendor evaluation skill for Claude Code — domain-expert questions, vendor AI agent conversations, evidence-based scoring

UnauthScout is an OSINT (Open Source Intelligence) tool developed in Bash for passive exploration of assets on version control platforms (GitLab and…

We collected existing open source code for malicious URL detection