
ore-mal-pkg-inspector
Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Defense Against the Shai-Hulud Supply Chain Attack


Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…


All-in-one tool for managing vulnerability reports from AppSec pipelines

SecureAI-Scan is a CLI tool that scans TypeScript and JavaScript codebases for security issues specific to AI-powered apps — prompt injection, MCP…

A lightweight, cross-platform CLI tool that scans your filesystem to detect exposed secrets, API keys, and tokens. Built with Go for maximum…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.

A project security/vulnerability/risk scanning tool

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Automatic SSTI detection tool with interactive interface

Security-focused static analysis for the Phoenix Framework

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.