JSPM

Found 190 results for devsecops

kubernetes-fluent-client

A @kubernetes/client-node fluent API wrapper that leverages K8s Server Side Apply.

  • v3.11.7
  • 60.50
  • Published

carrot-scan

Command-line tool for detecting vulnerabilities in files and directories.

  • v6.0.1
  • 59.71
  • Published

sentix

Autonomous multi-agent DevSecOps pipeline CLI

  • v2.47.0
  • 50.76
  • Published

ship-safe

AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a

  • v9.3.0
  • 45.12
  • Published

securewithtrace

Official Trace CLI for vulnerability intelligence in your terminal

  • v0.26.1
  • 43.93
  • Published

@nodatachat/guard

NoData Guard — continuous security scanner. Runs locally, reports only metadata. Your data never leaves your machine.

  • v4.3.2
  • 43.82
  • Published

@xdev-asia/xdev-knowledge-mcp

MCP Server - Toàn bộ kiến thức xDev.asia: 57 series, 1200+ lessons, blog, showcase (AI, Architecture, DevSecOps, Programming)

  • v1.0.82
  • 43.22
  • Published

sbom-sentinel

Automated SBOM generation and vulnerability scanning for multiple repositories. Generates CycloneDX SBOMs, scans with Trivy, and notifies via Slack/email.

  • v0.8.1
  • 42.17
  • Published

xploitscan

AI security scanner for vibe-coded apps. Find vulnerabilities before attackers do.

  • v1.1.7
  • 41.03
  • Published

cognium

Semantic static analysis engine for detecting security vulnerabilities via taint tracking

  • v1.7.1
  • 39.89
  • Published

eduskills-cybersecurity

Production-grade security hardening skill for Claude Code — AI/vibe-coded projects, OWASP Top 10, zero-trust, red-team, Supabase RLS, compliance (SOC 2, PCI-DSS, GDPR/LGPD)

  • v1.0.7
  • 39.86
  • Published

watson-watchdog

watson-watchdog é uma ferramenta que usa inteligência artificial para verificar vulnerabilidades em dependências de projetos Node.js, analisando o package-lock.json. Ideal para integração em CI/CD pipelines.

  • v1.0.6
  • 39.71
  • Published

sec-gate

Pre-commit security gate for OWASP Top 10 2021 — SAST, SCA and misconfig checks for Node/Express, Go and React codebases

  • v0.2.1
  • 38.22
  • Published

sentinelci

AI-Powered Security Scanning and Autonomous Remediation Platform

  • v1.0.9
  • 37.67
  • Published

asyntax-cli

Asyntax AI — security-scan your codebase from the terminal

  • v0.3.6
  • 37.57
  • Published

lula2

A tool for managing compliance as code in your GitHub repositories.

  • v0.9.5
  • 37.39
  • Published

modality-safe

Advanced security scanner that detects API key leaks and sensitive information in source code. Scans TypeScript, JavaScript, Markdown, and configuration files for AWS keys, OpenAI tokens, GitHub/GitLab PATs, Slack/Discord tokens, JWT tokens, and other cre

  • v0.4.1
  • 37.08
  • Published

breach-gate

OWASP API security scanner with AI-assisted behavioral testing, static analysis, container scanning, and GraphQL probing.

  • v1.2.3
  • 36.81
  • Published

autoremediator

Agentic CVE remediation platform for Node.js. Correlates threat intelligence, applies policy-governed fixes, and delivers auditable remediation outcomes across CI/CD pipelines, agent workflows, and service portfolios.

  • v0.14.1
  • 35.85
  • Published

codeslick-cli

CodeSlick CLI tool for pre-commit security scanning — 308 checks across JS, TS, Python, Java, Go

  • v1.6.0
  • 35.75
  • Published

@bhaveshbhardwaj7/adbis-dashboard

<div align="center"> <h1>🌌 ADBIS Dashboard</h1> <p><b>The Real-Time Acoustic & Visual Cyber-Defense Console</b></p>

    • v2.0.3
    • 34.53
    • Published

    flieger

    Safe share for AI-built apps. One command scans for exposed API keys, leaked .env files, and open CORS — then opens a live URL via Cloudflare Tunnel. Agent-native (Claude Code, Cursor, Cline). Free forever; Pro for stable *.flieger.app subdomains.

    • v0.2.1
    • 34.41
    • Published

    slash-do

    Curated slash commands for AI coding assistants — Claude Code, OpenCode, Gemini CLI, and Codex

    • v2.14.1
    • 34.21
    • Published

    @tinydarkforge/secgate

    Tiny security gate for CI/CD — orchestrates Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit with a premium HTML report.

    • v0.2.4
    • 33.74
    • Published

    syntropylog

    Structured observability framework for Node.js — declarative logging, masking, compliance, and tracing for high-demand environments.

    • v1.0.0-rc.2
    • 33.66
    • Published

    @bhaveshbhardwaj7/adbis-control-plane

    <div align="center"> <h1>⚙️ ADBIS Control Plane</h1> <p><b>The High-Performance, Asynchronous Incident Response Backend</b></p>

      • v2.0.3
      • 33.35
      • Published

      @fjbarrena/dtrack-cli

      A small CLI to upload BOM files to OWASP Dependency Track (https://dependencytrack.org/) tool using CI/CD pipelines

        • v1.0.12
        • 33.29
        • Published

        ferret-scan

        Static security scanner for AI CLI and MCP configurations — detects credential leaks, prompt injection, jailbreaks, and supply chain risks

        • v2.4.0
        • 33.28
        • Published

        @arcane-spark/ubel-node

        Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.

        • v0.2.0
        • 33.06
        • Published

        @bhaveshbhardwaj7/adbis-shared

        <div align="center"> <h1>🛡️ ADBIS Shared Core</h1> <p><b>The Immutable Zero-Trust Detection & Policy Engine for ADBIS</b></p>

          • v2.0.3
          • 32.93
          • Published

          react2shell-guard

          Security scanner for CVE-2025-55182 - Critical React Server Components RCE vulnerability. Scan lockfiles, SBOMs, Docker images, and live URLs.

          • v1.1.1
          • 31.25
          • Published

          github-security-mcp

          GitHub security posture audit tools for AI agents — organization, repository, Actions, secrets, supply chain analysis via MCP

          • v0.1.0
          • 31.17
          • Published

          vibecheck-ai

          VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

          • v6.0.5
          • 31.15
          • Published

          @finktech/mcp-verify

          Enterprise-grade security validation and testing tool for MCP servers (Model Context Protocol)

          • v1.0.2
          • 30.25
          • Published

          shakerscan

          First-party CLI for the ShakerScan security control plane

          • v0.2.2
          • 30.17
          • Published

          vibecipher

          VibeSecurity — Auditoria de segurança para quem cria com IA. Secrets, vulnerabilidades e rotas sem auth.

          • v1.1.26
          • 29.97
          • Published

          @cveriskpilot/scan

          Compliance as a Service CLI — scan dependencies, secrets, and IaC, then auto-map every finding to NIST 800-53, SOC 2, CMMC, FedRAMP, ASVS, and SSDF controls

          • v0.1.17
          • 29.19
          • Published

          @a-r3/diagno

          Universal repository diagnostic and security scanning tool with explainable AI

            • v1.6.11
            • 29.18
            • Published

            aws-secrets-manager-wrapper

            A TypeScript wrapper for AWS Secrets Manager that simplifies common operations and provides a more user-friendly interface.

            • v0.0.5
            • 28.71
            • Published

            cdktg

            Agile Threat Modeling as Code

            • v0.0.40
            • 28.69
            • Published

            @cruxet/mcp-audit

            Local, zero-setup security linter for your MCP client configs. Catches command injection, hardcoded secrets, insecure transports, and known CVEs across Cursor, Claude, Windsurf, VSCode, Continue, Codex, and Zed. No account, no API calls, no data leaves yo

            • v0.2.0
            • 28.58
            • Published

            @cybrium-ai/mcp-server

            MCP server for AI security + AI governance + AI inventory + code security. Lets Claude, Cursor, Windsurf, Cline invoke cyscan (SAST/SCA/secrets — 1,815 rules / 75+ languages), cyweb (web vulnerability scanner), cyprobe (network discovery), cyradar (discov

            • v0.3.0
            • 28.41
            • Published

            argus-agent

            All-seeing security and code quality agent for Claude Code - monitors code quality, security vulnerabilities, and integrates with SonarQube, Fortify, and JFrog

            • v1.0.1
            • 28.37
            • Published

            security-mcp

            AI security MCP server and enforcement gate for Claude Code, Cursor, GitHub Copilot, Codex, Replit, and any MCP-compatible editor. Applies OWASP, MITRE ATT&CK, NIST, Zero Trust, PCI DSS, SOC 2, and ISO 27001.

            • v1.1.4
            • 27.84
            • Published

            codedrift

            Guardrails for AI-assisted development - Detects IDOR, missing input validation, hardcoded secrets, and other critical bugs in AI-generated code

            • v1.2.12
            • 27.84
            • Published

            @vibecheckai/cli

            Vibecheck CLI - Ship with confidence. One verdict: SHIP | WARN | BLOCK.

            • v4.0.2
            • 27.75
            • Published

            @monodox/bugbase

            Bugbase CLI for CVE scanning, secret detection, and predictive security analysis.

            • v0.2.0
            • 27.53
            • Published

            guardlog

            Lightweight real-time CLI security log analyzer — detects brute force, SQL injection, XSS, and suspicious bots in server logs

            • v1.0.1
            • 27.34
            • Published

            hzsec-cli

            Local-first security scanner. Finds secrets, misconfigs, and unsafe code patterns. Runs in CI. Free, MIT-licensed, no telemetry.

            • v1.0.0
            • 27.18
            • Published

            @secrethub/cli

            A secrets management platform that every engineer can use with minimal code changes.

            • v0.44.1
            • 27.18
            • Published

            guardlink

            GuardLink — Security annotations for code. Threat modeling that lives in your codebase.

            • v1.4.3
            • 27.13
            • Published

            @fortify/setup

            Bootstrap and run fcli fortify-setup action in any environment

            • v2.1.3
            • 26.80
            • Published

            @swasti-sundar/console-guard

            Security-focused CLI that scans JavaScript/TypeScript codebases for console statements that may leak sensitive data, classifies them by risk level, and blocks risky commits via a pre-commit hook.

            • v1.0.1
            • 26.71
            • Published

            @intentsolutionsio/security-pro-pack

            Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security

            • v1.0.0
            • 26.58
            • Published

            @inkog-io/mcp

            Security co-pilot for AI agents. Scan for vulnerabilities, verify governance, audit MCP servers, and generate compliance reports — all from Claude, Cursor, or any MCP client.

            • v1.0.21
            • 26.28
            • Published

            guardrail-cli-tool

            Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

            • v2.5.4
            • 26.24
            • Published

            meok-mcp-sdlc-audit

            MCP server for SDLC audit and secure development lifecycle checks

            • v1.0.0
            • 26.21
            • Published

            firmis-cli

            The security layer for AI agents — platform-agnostic threat detection with 300+ rules, runtime blocking, and remediation guidance. Continuous protection.

            • v2026.1.4
            • 26.03
            • Published

            claude-audit

            AI-powered codebase auditor — security, quality, performance, architecture & more

            • v0.1.1
            • 25.93
            • Published

            @sathyendra/security-checker

            Stop npm supply-chain attacks before they execute. Zero-dependency security scanner: malicious package detection, lockfile audit, dropper detection, integrity checks, OWASP A03/A05/A08/A10 coverage, CycloneDX SBOM & VEX reports, provenance verification, s

            • v1.26.0
            • 25.90
            • Published

            worm-sign

            A security scanner that detects npm packages compromised by supply chain attacks, including the Axios attack (March 2026) and Shai Hulud malware.

            • v4.0.0
            • 25.59
            • Published

            n8n-nodes-snyk

            A comprehensive n8n community node for Snyk security platform providing 12 resources and 60+ operations for vulnerability management, project monitoring, and security reporting.

            • v1.0.0
            • 25.52
            • Published

            cerber-core

            Prevent secrets (API keys, passwords) and console.log in commits. Zero-config pre-commit hooks with Husky auto-install. Blocks Stripe, GitHub, AWS credentials out-of-the-box. 357+ teams protected.

            • v1.1.12
            • 25.46
            • Published

            verification-layer

            Open-source HIPAA compliance scanner for healthcare code. 140+ rules, 5 HIPAA categories. CLI + CI/CD + VS Code.

            • v0.24.4
            • 25.29
            • Published

            aura-security

            AI-powered security scanner with 9-agent swarm. Detect secrets, vulnerabilities, attack paths. CLI, API, or cloud dashboard at app.aurasecurity.io

            • v1.0.3
            • 25.29
            • Published

            @guard0/g0

            Background check for AI agents — discover, assess, and test before you ship

            • v2.0.0
            • 25.14
            • Published

            readtheplan

            Terraform plan risk explainer — reads `terraform plan` and classifies each change as safe/review/dangerous/irreversible. Pre-MVP namespace placeholder.

            • v0.0.1
            • 24.88
            • Published

            @sonofg0tham/quell-scanner

            Offline secret-detection engine. Regex patterns plus Shannon entropy. Zero runtime dependencies. The core scanner behind the Quell VSCode extension.

            • v0.1.0
            • 24.57
            • Published

            @xiaopin44/sec-command-warning

            Detect dangerous shell commands (rm -rf, DROP TABLE, git force push, etc.) before they execute. CLI tool for CI/CD and development security.

            • v1.0.0
            • 24.50
            • Published

            titanshield

            TitanShieldAI CLI — AI-powered security scanner for your codebase. Zero config. Under 2 minutes.

            • v0.6.4
            • 24.16
            • Published

            assumer-cli

            Assume IAM roles between AWS accounts

            • v2.1.4
            • 24.16
            • Published

            @shiftleftpt/sbd-toe-mcp

            MCP server for the SbD-ToE (Security by Design — Theory of Everything) security manual — structured tools for Claude, GitHub Copilot and other MCP clients

            • v0.7.7
            • 23.94
            • Published

            friskit

            Frisk your vibe-coded app before someone else does.

            • v0.1.0
            • 23.92
            • Published

            @merupatel/reachable

            Local-first vulnerability reachability CLI for JavaScript and TypeScript

            • v1.0.8
            • 23.83
            • Published

            purpleteam

            CLI for driving purpleteam -- security regression testing SaaS

            • v4.0.0-alpha.3
            • 23.71
            • Published

            agentlint

            Static analysis and security scanner for AI agent configuration files

            • v0.3.0
            • 23.70
            • Published

            mcp-server-security-audit

            MCP server for MetalTorque Security Audit — gives AI agents the ability to scan websites for security vulnerabilities.

            • v1.0.3
            • 22.93
            • Published

            @bene-npm/shield-ui

            Security-themed React component library for dashboards, scanners, and threat visualization

            • v2.0.3
            • 22.88
            • Published

            @ship-safe/cli

            Security scanner for AI-generated code — find vulnerabilities before you ship

            • v1.1.14
            • 22.64
            • Published

            @ayurak/sdk

            Aribot Security Platform SDK by Aristiun & Ayurak - Threat modeling, compliance, and cloud security APIs

            • v2.0.1
            • 22.56
            • Published

            @custodia/cli

            Secure Code — scan, fix, and automate security for any codebase. SOC 2, NIST CSF, OWASP Top 10 & CWE.

              • v2.7.0
              • 21.91
              • Published

              guardrail-cli

              Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

              • v2.5.4
              • 21.84
              • Published

              @ferrierepete/codewatch

              Security pattern detector for AI-generated code — catches the dangerous patterns AI coding agents introduce, directly in your git workflow

                • v1.0.0
                • 21.77
                • Published

                trustfix

                Non-Human Identity Security Platform — detect OIDC trust policy misconfigurations, validate fixes with a 6-layer Policy Intelligence Engine, and auto-generate Terraform PRs.

                • v1.0.4
                • 21.72
                • Published

                ngx-security-audit

                The most comprehensive Angular security auditing tool. 150+ rules, 10 scan types (OWASP, API security, performance, accessibility, dependency audit, hacking, complexity, code quality). Auto-fix suggestions, HTML dashboard, SVG badge generation, SARIF expo

                • v2.0.1
                • 21.59
                • Published

                @snytch/nextjs

                Bundle scanning, NEXT_PUBLIC_ exposure detection, and environment drift for Next.js

                  • v0.15.0
                  • 21.59
                  • Published

                  @syntropysoft/praetorian

                  Praetorian CLI – A universal multi-environment configuration validator for DevSecOps teams. Validate, compare, and secure YAML/ENV files with ease.

                  • v0.0.4-alpha
                  • 21.55
                  • Published

                  blackduck-polaris-mcp-server

                  Feature-rich MCP server for Black Duck Polaris — trigger SAST/SCA/DAST scans, query findings, generate reports (SBOM, SPDX, CycloneDX), manage policies, triage issues, and more. Works with Claude Code, Claude Desktop, GitHub Copilot, Cursor, and any MCP-c

                    • v0.3.1
                    • 21.47
                    • Published

                    @ferrierepete/mcpshield

                    Security scanner for MCP (Model Context Protocol) servers — detect supply chain risks, permission overreach, and misconfigurations

                    • v0.2.2
                    • 21.33
                    • Published

                    @tonyjnr/apishield

                    API security scanner for indie developers — detects auth gaps, sensitive data leaks, and more in OpenAPI/Swagger specs.

                    • v1.1.1
                    • 21.05
                    • Published

                    @raghulm/aegis-mcp

                    DevSecOps-focused MCP server for AWS, Kubernetes, CI/CD, and security tooling.

                    • v1.0.9
                    • 20.90
                    • Published

                    @kenjiifx/permissionguard

                    AWS IAM security scanner CLI that detects overly broad permissions, scores risk, and suggests safer policy changes.

                    • v0.1.0
                    • 20.82
                    • Published

                    agent-security-policies

                    Portable, standards-backed security policies for any AI coding agent. One command to install OWASP, CWE, NIST rules + security skills.

                    • v1.5.7
                    • 20.77
                    • Published

                    dep-oracle

                    Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis for your supply chain.

                    • v1.4.0
                    • 20.58
                    • Published

                    cw-kfc

                    A @kubernetes/client-node fluent API wrapper that leverages K8s Server Side Apply.

                    • v4.0.5
                    • 20.50
                    • Published

                    snykcon

                    A CLI for Snyk's SnykCon 2020 DevSecOps and Developer-first security conference

                    • v1.0.2
                    • 20.45
                    • Published

                    crowbar-security

                    autonomous black-box web penetration testing. give it a URL, it finds everything exploitable.

                    • v0.1.3
                    • 20.27
                    • Published

                    lula-next

                    Reports Reports and exports compliance status for defined controls.

                    • v0.0.2
                    • 19.85
                    • Published

                    sentinelflow

                    AI agent governance platform — static scanning + runtime interception for Claude Code, Cursor, GitHub Copilot, Codex, LangChain, CrewAI, and Kiro. Blocks dangerous tool calls in real-time.

                    • v0.3.1
                    • 19.69
                    • Published

                    get-shit-secured

                    Security workflow installer for AI coding runtimes (Claude, Codex, and more)

                    • v0.0.3
                    • 19.49
                    • Published

                    mantis-redteam

                    Open-source CLI toolkit for automated red-teaming of LLM-powered applications

                    • v0.2.9
                    • 19.32
                    • Published

                    kguard

                    The missing security layer for open source projects. Scan, fix, and enforce secret hygiene, supply chain integrity, and project health.

                    • v0.1.0
                    • 19.19
                    • Published

                    skillshield

                    Runtime security for AI Agent Skills — Scan, sandbox & enforce. Detect prompt injection, memory poisoning, supply chain attacks. 72+ patterns, 14 categories. The firewall Snyk and Cisco don't build.

                    • v2.1.0
                    • 19.02
                    • Published

                    claudesec

                    DevSecOps toolkit for AI-assisted secure development — security scanner, ISMS dashboard, asset management

                    • v0.6.1
                    • 18.70
                    • Published

                    sast-scan

                    A lightweight, extensible Static Application Security Testing (SAST) tool for JavaScript. Detects vulnerabilities like XSS, SQL injection, hardcoded secrets, prototype pollution, and more — with CWE references, severity ratings, and context-aware reportin

                    • v2.1.0
                    • 18.54
                    • Published

                    zyph

                    A dependency scanner that detects suspicious code.

                    • v0.0.7
                    • 18.51
                    • Published

                    @devsecurex/cli

                    DevSecureX CLI - Advanced security scanning tool for developers. Detect vulnerabilities across 20+ programming languages with comprehensive SAST, dependency analysis, secrets detection, and compliance reporting. Integrates seamlessly with CI/CD pipelines

                    • v0.3.0
                    • 18.30
                    • Published

                    venom-pentest

                    Venom — Autonomous AI pentester for developers. Find exploits AND fix them.

                    • v1.2.1
                    • 18.17
                    • Published

                    vibesafe-cli

                    AI Code Security Auditor — catches vulnerabilities that LLMs introduce and SonarQube misses. Purpose-built for AI-generated code with educational feedback.

                    • v1.0.2
                    • 18.15
                    • Published

                    vaultace-cli

                    AI-powered security scanner that detects vulnerabilities in AI-generated code. Proactive scanning, autonomous fixing, and emergency response for modern development teams.

                    • v1.0.3
                    • 18.05
                    • Published

                    opensecurity

                    Open-source CLI for scanning repositories for security risks across code, infra, and dependencies.

                    • v0.3.0
                    • 18.05
                    • Published

                    assumer

                    Assume AWS IAM roles between Control account and Target accounts

                    • v0.2.1
                    • 17.73
                    • Published

                    @jobersteadt/vibescan

                    Developer-first JavaScript/TypeScript security scanner with static analysis, proof-oriented tests, secure-arch checks, and AI rule export.

                    • v1.1.1
                    • 17.59
                    • Published

                    teachable-machine.js

                    A robust and optimized JavaScript library for integrating Google's Teachable Machine models, supporting various image sources and providing efficient classification capabilities.

                    • v2.0.2
                    • 17.53
                    • Published

                    @jackdog668/vibeaudit

                    Security audit CLI for AI-generated codebases. Find the time bombs before they blow.

                    • v1.1.0
                    • 16.86
                    • Published

                    vibecheckdev

                    AI security scanner for vibe-coded apps. Find vulnerabilities before attackers do.

                    • v0.4.0
                    • 16.70
                    • Published

                    @quantumtiger/qv

                    Quantum Viper CLI (qv) - Professional AI-Powered Security Analysis

                    • v4.0.0
                    • 16.67
                    • Published

                    guardog

                    Secret scanning in your codebase, the FOSS way.

                      • v1.0.0
                      • 16.57
                      • Published

                      password-tester

                      Test password/phrases to ensure strong entropy and no reuse from a password breach, based on the latest guidance.

                      • v1.2.3
                      • 16.50
                      • Published

                      clawhatch

                      Security scanner for OpenClaw AI agents — 100-point audit with auto-fix

                      • v0.1.0
                      • 16.07
                      • Published

                      sealight

                      CLI tool to detect hardcoded secrets and sensitive data in codebases.

                      • v0.1.4
                      • 15.77
                      • Published

                      @tytspot/cli

                      TYTSPOT CLI for running security scans, reviewing findings, and working with reports from the terminal.

                      • v0.2.3
                      • 15.70
                      • Published

                      @custodia/mcp

                      MCP server for Custodia — scan GitHub repos for security vulnerabilities from Claude Desktop, Cursor, and Claude.ai.

                        • v1.2.0
                        • 15.70
                        • Published

                        @ayurak/aribot

                        Aribot Security Platform SDK - Threat modeling, compliance, cloud security, and AI-powered security analysis

                        • v2.0.1
                        • 15.66
                        • Published

                        securedx

                        Graduated security gates for DevSecOps pipelines - A developer-centric approach to security enforcement with configurable severity thresholds and productivity analytics

                          • v2.0.1
                          • 15.37
                          • Published

                          mcp-security-auditor

                          Security scanner for MCP (Model Context Protocol) servers. Detect vulnerabilities, secrets, injection risks, and misconfigurations before deployment.

                          • v1.0.2
                          • 15.28
                          • Published

                          @masonator/get-mcp-keys

                          A lightweight utility that securely loads API keys for Cursor MCP servers from your home directory, preventing accidental exposure of secrets in repositories. Keep your credentials safe while maintaining seamless integration with AI coding assistants.

                          • v1.0.1
                          • 15.01
                          • Published

                          leak-proof

                          Zero-config Git pre-commit hook that blocks secrets (AWS keys, API tokens, .env files) from being committed. Auto-installs for your entire team.

                          • v1.1.0
                          • 14.95
                          • Published

                          @sixthwall/cli

                          Security scanner for AI-generated code. Detect vulnerabilities in Claude Code, Cursor, and Copilot output. Fix Packs with Claude prompts included.

                          • v0.2.1
                          • 14.54
                          • Published

                          n8n-nodes-pytenable

                          Un nodo de n8n para interactuar con la API de Tenable usando Pytenable en un sandbox de Docker.

                            • v1.0.1
                            • 14.47
                            • Published

                            ordo-cli

                            Ordo security scanner CLI - catch vulnerabilities before they cost you money

                            • v1.0.7
                            • 14.47
                            • Published

                            depsafe

                            Know what your dependencies actually do to your code. Usage-level CVE scoping, dead-weight detection, and health scoring for any GitHub repo across 11+ ecosystems.

                            • v1.0.0
                            • 14.40
                            • Published

                            @lxgicstudios/ai-auth-check

                            AI-powered auth security auditor - find vulnerabilities in your authentication code using GPT

                            • v1.0.2
                            • 14.40
                            • Published

                            fixyoursecret

                            CLI tool to detect leaked secrets, frontend exposure, and generate safe fixes.

                            • v0.4.3
                            • 14.38
                            • Published

                            secretsentry

                            A tool for finding leaked secrets in the code

                            • v1.0.1
                            • 14.29
                            • Published

                            hardcoded-api-key-detector

                            Comprehensive security tool to detect hardcoded API keys, tokens, and sensitive credentials in your codebase with 245+ detection patterns, entropy analysis, and baseline filtering

                            • v1.0.0
                            • 14.16
                            • Published

                            zin-adk

                            ZAK — Zeron Agentic Kit, open-source ADK for building autonomous cybersecurity agents. Build, deploy, and govern autonomous cybersecurity agents.

                            • v0.1.5
                            • 13.99
                            • Published

                            bodhi-commit-genius-js

                            🚀 Smart commit message generator with AI - supports local LLMs and cloud APIs

                            • v1.0.0
                            • 13.96
                            • Published

                            gsec-scanner

                            Scan git commit history for leaked secrets, API keys, and tokens by username. Find what was deleted but never truly gone.

                            • v1.0.0
                            • 13.69
                            • Published

                            @unitoneai/skills

                            45 security skills for AI coding agents — Claude Code, Gemini CLI, Cursor, Codex, and more

                            • v1.0.0
                            • 13.63
                            • Published

                            @firmislabs/firmis

                            AI agent security platform — scan, fix, monitor, and pentest MCP servers, Claude skills, Codex plugins, Cursor extensions, and 5 more platforms. 227 rules across 17 threat categories.

                            • v2.0.0
                            • 13.61
                            • Published

                            @vibecheckdev/vibecheckai

                            VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

                            • v6.0.6
                            • 13.41
                            • Published

                            @szcn/sentinelreview

                            AI-powered code review — security (OWASP Top 10), code quality, standards enforcement, and custom rules. 6 providers (Ollama free/local, Gemini, Groq, DeepSeek, OpenAI, Anthropic). MCP server for Cursor, Windsurf, VS Code, Claude Desktop + CLI + Node API.

                              • v1.0.1
                              • 13.22
                              • Published

                              @yanrix/action

                              Yanrix GitHub Action — AI-powered STRIDE threat modeling for pull requests. Forthcoming release. Visit yanrix.dev for updates.

                              • v0.0.1
                              • 13.03
                              • Published

                              i4q-dependencytrack

                              CLI to upload BOM files to Dependency-Track (https://dependencytrack.org/) tool using CI/CD pipelines

                                • v1.0.2
                                • 12.87
                                • Published

                                axiontrix-event

                                An advanced, highly resilient Event Emitter built on top of the native Node.js events module. It is designed to facilitate seamless, secure, and reliable event communication between two or more distinct Node.js applications across a network.

                                • v1.0.1
                                • 12.80
                                • Published

                                uncloak-security

                                Security scanner for AI-generated and vibe-coded projects. Detects secrets, injection attacks, weak crypto, backdoors, and more.

                                • v2.3.1
                                • 12.52
                                • Published

                                @guardrailai/cli

                                Guardrail CLI — Ship with confidence. AI-native code scanning, security analysis, and quality gates.

                                • v2.6.0
                                • 12.41
                                • Published

                                oidc-audit

                                Scan AWS IAM roles for OIDC trust policy misconfigurations in GitHub Actions. Free CLI by TrustFix.

                                • v1.0.0
                                • 12.41
                                • Published

                                guardian-config-check

                                Build configuration integrity scanner — detects supply chain compromise indicators in config files

                                • v1.0.0
                                • 12.41
                                • Published

                                guardrails-scanner

                                AI-powered security scanner that automatically fixes vulnerabilities - SQL injection, XSS, secrets exposure, and more. Not just detection, but intelligent autofix before commit.

                                • v1.0.6
                                • 11.61
                                • Published

                                shipguard-cli

                                AI-powered security scanner with Claude API integration and MCP server support

                                • v2.0.0
                                • 11.39
                                • Published

                                devsecops-git-guardian

                                🛡️ Block secrets, misconfigurations, and vulnerabilities before they reach your repository. Real-time security scanning with inline diagnostics.

                                  • v1.4.0
                                  • 11.26
                                  • Published

                                  ai-auth-check

                                  Audit your auth implementation for security flaws

                                  • v1.0.1
                                  • 10.95
                                  • Published

                                  claude-aspm-scan

                                  Claude Code skill for Application Security Posture Management — runs Semgrep SAST and optional Shannon pentesting, generates ASPM_SCAN.md reports

                                  • v1.0.0
                                  • 10.78
                                  • Published

                                  secret-sweep

                                  🔐 Scan your entire git history for accidentally committed secrets. Rotate, fix, and prevent credential exposure.

                                  • v1.0.0
                                  • 10.37
                                  • Published

                                  codesentinel-ai

                                  AI-powered security scanner for your codebase. Scan for vulnerabilities, get risk scores, auto-report on GitLab MRs.

                                  • v1.0.0
                                  • 10.05
                                  • Published

                                  @grepture/cli

                                  AI security scanner for developers — Scan for PII, secrets, prompt injection, and unsafe AI SDK usage.

                                  • v0.1.0
                                  • 9.93
                                  • Published

                                  @sixthwall/mcp-server

                                  MCP server for SixthWall AI code security scanner. Integrates with Claude Code for automatic vulnerability detection with Fix Packs.

                                  • v0.1.0
                                  • 9.87
                                  • Published

                                  supamend

                                  Pluggable DevSecOps Security Scanner with 10+ scanners and multiple reporting channels

                                  • v1.0.0-beta.1
                                  • 9.68
                                  • Published

                                  @yanrix/schemas

                                  Yanrix schema definitions — shared types and validation schemas for the Yanrix threat modeling platform. Forthcoming release. Visit yanrix.dev for updates.

                                  • v0.0.1
                                  • 9.68
                                  • Published

                                  vibecheck-cli-tool

                                  Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

                                  • v2.5.2
                                  • 9.68
                                  • Published

                                  dti4q

                                  CLI to upload BOM files to Dependency-Track (https://dependencytrack.org/) tool using CI/CD pipelines

                                    • v1.0.0
                                    • 9.42
                                    • Published

                                    leaksniff

                                    Smell leaks before attackers do.

                                    • v0.1.0
                                    • 9.39
                                    • Published

                                    secure-dev-ai

                                    Security by design CLI for AI-assisted development - scans projects and guards autonomous agent runs

                                    • v0.1.0
                                    • 9.33
                                    • Published

                                    @probex-scan/agent

                                    ProbeX Security Agent — 9 scan engines, one command. Local-first DevSecOps scanning with cloud upload.

                                    • v1.0.0
                                    • 8.72
                                    • Published

                                    agent-mcp-guard

                                    Open-source CLI scanner for risky MCP server and AI agent tool configuration.

                                    • v0.4.9
                                    • 0.00
                                    • Published

                                    web-secure-verification

                                    Security scanning CLI for React and Next.js — detects CVEs, secrets, license risks, supply chain threats, hydration bugs, RSC boundary violations, and more.

                                      • v1.0.1
                                      • 0.00
                                      • Published

                                      @atofinite5/sork-cli

                                      Sorkcloud CLI — AI-powered security pipeline for Node.js projects. Scans, triages, fixes, verifies, and supports multiple AI agents (Claude, OpenAI, Codex, Gemini, Mistral, Llama). Works with BYOK or sorkcloud.space-managed keys.

                                      • v1.2.1
                                      • 0.00
                                      • Published