JSPM

Found 190 results for devsecops

@merupatel/reachable

Local-first vulnerability reachability CLI for JavaScript and TypeScript

  • v1.0.8
  • 22.91
  • Published

@bene-npm/shield-ui

Security-themed React component library for dashboards, scanners, and threat visualization

  • v2.0.3
  • 22.89
  • Published

mcp-server-security-audit

MCP server for MetalTorque Security Audit — gives AI agents the ability to scan websites for security vulnerabilities.

  • v1.0.3
  • 22.87
  • Published

@ship-safe/cli

Security scanner for AI-generated code — find vulnerabilities before you ship

  • v1.1.14
  • 22.65
  • Published

@ayurak/sdk

Aribot Security Platform SDK by Aristiun & Ayurak - Threat modeling, compliance, and cloud security APIs

  • v2.0.1
  • 22.57
  • Published

@custodia/cli

Secure Code — scan, fix, and automate security for any codebase. SOC 2, NIST CSF, OWASP Top 10 & CWE.

    • v2.7.0
    • 21.85
    • Published

    guardrail-cli

    Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

    • v2.5.4
    • 21.79
    • Published

    trustfix

    Non-Human Identity Security Platform — detect OIDC trust policy misconfigurations, validate fixes with a 6-layer Policy Intelligence Engine, and auto-generate Terraform PRs.

    • v1.0.4
    • 21.73
    • Published

    @ferrierepete/codewatch

    Security pattern detector for AI-generated code — catches the dangerous patterns AI coding agents introduce, directly in your git workflow

      • v1.0.0
      • 21.72
      • Published

      ngx-security-audit

      The most comprehensive Angular security auditing tool. 150+ rules, 10 scan types (OWASP, API security, performance, accessibility, dependency audit, hacking, complexity, code quality). Auto-fix suggestions, HTML dashboard, SVG badge generation, SARIF expo

      • v2.0.1
      • 21.60
      • Published

      @snytch/nextjs

      Bundle scanning, NEXT_PUBLIC_ exposure detection, and environment drift for Next.js

        • v0.15.0
        • 21.60
        • Published

        @syntropysoft/praetorian

        Praetorian CLI – A universal multi-environment configuration validator for DevSecOps teams. Validate, compare, and secure YAML/ENV files with ease.

        • v0.0.4-alpha
        • 21.56
        • Published

        blackduck-polaris-mcp-server

        Feature-rich MCP server for Black Duck Polaris — trigger SAST/SCA/DAST scans, query findings, generate reports (SBOM, SPDX, CycloneDX), manage policies, triage issues, and more. Works with Claude Code, Claude Desktop, GitHub Copilot, Cursor, and any MCP-c

          • v0.3.1
          • 21.48
          • Published

          @ferrierepete/mcpshield

          Security scanner for MCP (Model Context Protocol) servers — detect supply chain risks, permission overreach, and misconfigurations

          • v0.2.2
          • 21.18
          • Published

          @tonyjnr/apishield

          API security scanner for indie developers — detects auth gaps, sensitive data leaks, and more in OpenAPI/Swagger specs.

          • v1.1.1
          • 21.06
          • Published

          @raghulm/aegis-mcp

          DevSecOps-focused MCP server for AWS, Kubernetes, CI/CD, and security tooling.

          • v1.0.9
          • 20.91
          • Published

          @kenjiifx/permissionguard

          AWS IAM security scanner CLI that detects overly broad permissions, scores risk, and suggests safer policy changes.

          • v0.1.0
          • 20.77
          • Published

          agent-security-policies

          Portable, standards-backed security policies for any AI coding agent. One command to install OWASP, CWE, NIST rules + security skills.

          • v1.5.7
          • 20.72
          • Published

          dep-oracle

          Predictive dependency security engine. Trust scores, zombie detection, blast radius analysis for your supply chain.

          • v1.4.0
          • 20.53
          • Published

          cw-kfc

          A @kubernetes/client-node fluent API wrapper that leverages K8s Server Side Apply.

          • v4.0.5
          • 20.45
          • Published

          snykcon

          A CLI for Snyk's SnykCon 2020 DevSecOps and Developer-first security conference

          • v1.0.2
          • 20.30
          • Published

          crowbar-security

          autonomous black-box web penetration testing. give it a URL, it finds everything exploitable.

          • v0.1.3
          • 20.22
          • Published

          lula-next

          Reports Reports and exports compliance status for defined controls.

          • v0.0.2
          • 19.86
          • Published

          sentinelflow

          AI agent governance platform — static scanning + runtime interception for Claude Code, Cursor, GitHub Copilot, Codex, LangChain, CrewAI, and Kiro. Blocks dangerous tool calls in real-time.

          • v0.3.1
          • 19.64
          • Published

          get-shit-secured

          Security workflow installer for AI coding runtimes (Claude, Codex, and more)

          • v0.0.3
          • 19.44
          • Published

          mantis-redteam

          Open-source CLI toolkit for automated red-teaming of LLM-powered applications

          • v0.2.9
          • 19.27
          • Published

          kguard

          The missing security layer for open source projects. Scan, fix, and enforce secret hygiene, supply chain integrity, and project health.

          • v0.1.0
          • 19.05
          • Published

          skillshield

          Runtime security for AI Agent Skills — Scan, sandbox & enforce. Detect prompt injection, memory poisoning, supply chain attacks. 72+ patterns, 14 categories. The firewall Snyk and Cisco don't build.

          • v2.1.0
          • 19.02
          • Published

          claudesec

          DevSecOps toolkit for AI-assisted secure development — security scanner, ISMS dashboard, asset management

          • v0.6.1
          • 18.71
          • Published

          sast-scan

          A lightweight, extensible Static Application Security Testing (SAST) tool for JavaScript. Detects vulnerabilities like XSS, SQL injection, hardcoded secrets, prototype pollution, and more — with CWE references, severity ratings, and context-aware reportin

          • v2.1.0
          • 18.50
          • Published

          zyph

          A dependency scanner that detects suspicious code.

          • v0.0.7
          • 18.37
          • Published

          @devsecurex/cli

          DevSecureX CLI - Advanced security scanning tool for developers. Detect vulnerabilities across 20+ programming languages with comprehensive SAST, dependency analysis, secrets detection, and compliance reporting. Integrates seamlessly with CI/CD pipelines

          • v0.3.0
          • 18.26
          • Published

          venom-pentest

          Venom — Autonomous AI pentester for developers. Find exploits AND fix them.

          • v1.2.1
          • 18.18
          • Published

          vibesafe-cli

          AI Code Security Auditor — catches vulnerabilities that LLMs introduce and SonarQube misses. Purpose-built for AI-generated code with educational feedback.

          • v1.0.2
          • 18.11
          • Published

          vaultace-cli

          AI-powered security scanner that detects vulnerabilities in AI-generated code. Proactive scanning, autonomous fixing, and emergency response for modern development teams.

          • v1.0.3
          • 18.01
          • Published

          opensecurity

          Open-source CLI for scanning repositories for security risks across code, infra, and dependencies.

          • v0.3.0
          • 18.01
          • Published

          assumer

          Assume AWS IAM roles between Control account and Target accounts

          • v0.2.1
          • 17.60
          • Published

          teachable-machine.js

          A robust and optimized JavaScript library for integrating Google's Teachable Machine models, supporting various image sources and providing efficient classification capabilities.

          • v2.0.2
          • 17.54
          • Published

          @jobersteadt/vibescan

          Developer-first JavaScript/TypeScript security scanner with static analysis, proof-oriented tests, secure-arch checks, and AI rule export.

          • v1.1.1
          • 17.46
          • Published

          @jackdog668/vibeaudit

          Security audit CLI for AI-generated codebases. Find the time bombs before they blow.

          • v1.1.0
          • 16.87
          • Published

          vibecheckdev

          AI security scanner for vibe-coded apps. Find vulnerabilities before attackers do.

          • v0.4.0
          • 16.71
          • Published

          @quantumtiger/qv

          Quantum Viper CLI (qv) - Professional AI-Powered Security Analysis

          • v4.0.0
          • 16.54
          • Published

          guardog

          Secret scanning in your codebase, the FOSS way.

            • v1.0.0
            • 16.53
            • Published

            password-tester

            Test password/phrases to ensure strong entropy and no reuse from a password breach, based on the latest guidance.

            • v1.2.3
            • 16.38
            • Published

            clawhatch

            Security scanner for OpenClaw AI agents — 100-point audit with auto-fix

            • v0.1.0
            • 16.03
            • Published

            @ayurak/aribot

            Aribot Security Platform SDK - Threat modeling, compliance, cloud security, and AI-powered security analysis

            • v2.0.1
            • 15.66
            • Published

            @tytspot/cli

            TYTSPOT CLI for running security scans, reviewing findings, and working with reports from the terminal.

            • v0.2.3
            • 15.66
            • Published

            @custodia/mcp

            MCP server for Custodia — scan GitHub repos for security vulnerabilities from Claude Desktop, Cursor, and Claude.ai.

              • v1.2.0
              • 15.66
              • Published

              sealight

              CLI tool to detect hardcoded secrets and sensitive data in codebases.

              • v0.1.4
              • 15.65
              • Published

              securedx

              Graduated security gates for DevSecOps pipelines - A developer-centric approach to security enforcement with configurable severity thresholds and productivity analytics

                • v2.0.1
                • 15.37
                • Published

                mcp-security-auditor

                Security scanner for MCP (Model Context Protocol) servers. Detect vulnerabilities, secrets, injection risks, and misconfigurations before deployment.

                • v1.0.2
                • 15.24
                • Published

                @masonator/get-mcp-keys

                A lightweight utility that securely loads API keys for Cursor MCP servers from your home directory, preventing accidental exposure of secrets in repositories. Keep your credentials safe while maintaining seamless integration with AI coding assistants.

                • v1.0.1
                • 15.02
                • Published

                leak-proof

                Zero-config Git pre-commit hook that blocks secrets (AWS keys, API tokens, .env files) from being committed. Auto-installs for your entire team.

                • v1.1.0
                • 14.95
                • Published

                @sixthwall/cli

                Security scanner for AI-generated code. Detect vulnerabilities in Claude Code, Cursor, and Copilot output. Fix Packs with Claude prompts included.

                • v0.2.1
                • 14.55
                • Published

                depsafe

                Know what your dependencies actually do to your code. Usage-level CVE scoping, dead-weight detection, and health scoring for any GitHub repo across 11+ ecosystems.

                • v1.0.0
                • 14.37
                • Published

                @lxgicstudios/ai-auth-check

                AI-powered auth security auditor - find vulnerabilities in your authentication code using GPT

                • v1.0.2
                • 14.37
                • Published

                n8n-nodes-pytenable

                Un nodo de n8n para interactuar con la API de Tenable usando Pytenable en un sandbox de Docker.

                  • v1.0.1
                  • 14.36
                  • Published

                  ordo-cli

                  Ordo security scanner CLI - catch vulnerabilities before they cost you money

                  • v1.0.7
                  • 14.36
                  • Published

                  fixyoursecret

                  CLI tool to detect leaked secrets, frontend exposure, and generate safe fixes.

                  • v0.4.3
                  • 14.35
                  • Published

                  secretsentry

                  A tool for finding leaked secrets in the code

                  • v1.0.1
                  • 14.30
                  • Published

                  hardcoded-api-key-detector

                  Comprehensive security tool to detect hardcoded API keys, tokens, and sensitive credentials in your codebase with 245+ detection patterns, entropy analysis, and baseline filtering

                  • v1.0.0
                  • 14.12
                  • Published

                  zin-adk

                  ZAK — Zeron Agentic Kit, open-source ADK for building autonomous cybersecurity agents. Build, deploy, and govern autonomous cybersecurity agents.

                  • v0.1.5
                  • 13.99
                  • Published

                  bodhi-commit-genius-js

                  🚀 Smart commit message generator with AI - supports local LLMs and cloud APIs

                  • v1.0.0
                  • 13.97
                  • Published

                  @unitoneai/skills

                  45 security skills for AI coding agents — Claude Code, Gemini CLI, Cursor, Codex, and more

                  • v1.0.0
                  • 13.63
                  • Published

                  gsec-scanner

                  Scan git commit history for leaked secrets, API keys, and tokens by username. Find what was deleted but never truly gone.

                  • v1.0.0
                  • 13.59
                  • Published

                  @firmislabs/firmis

                  AI agent security platform — scan, fix, monitor, and pentest MCP servers, Claude skills, Codex plugins, Cursor extensions, and 5 more platforms. 227 rules across 17 threat categories.

                  • v2.0.0
                  • 13.58
                  • Published

                  @vibecheckdev/vibecheckai

                  VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

                  • v6.0.6
                  • 13.31
                  • Published

                  @szcn/sentinelreview

                  AI-powered code review — security (OWASP Top 10), code quality, standards enforcement, and custom rules. 6 providers (Ollama free/local, Gemini, Groq, DeepSeek, OpenAI, Anthropic). MCP server for Cursor, Windsurf, VS Code, Claude Desktop + CLI + Node API.

                    • v1.0.1
                    • 13.22
                    • Published

                    @yanrix/action

                    Yanrix GitHub Action — AI-powered STRIDE threat modeling for pull requests. Forthcoming release. Visit yanrix.dev for updates.

                    • v0.0.1
                    • 13.00
                    • Published

                    i4q-dependencytrack

                    CLI to upload BOM files to Dependency-Track (https://dependencytrack.org/) tool using CI/CD pipelines

                      • v1.0.2
                      • 12.88
                      • Published

                      axiontrix-event

                      An advanced, highly resilient Event Emitter built on top of the native Node.js events module. It is designed to facilitate seamless, secure, and reliable event communication between two or more distinct Node.js applications across a network.

                      • v1.0.1
                      • 12.70
                      • Published

                      uncloak-security

                      Security scanner for AI-generated and vibe-coded projects. Detects secrets, injection attacks, weak crypto, backdoors, and more.

                      • v2.3.1
                      • 12.53
                      • Published

                      @guardrailai/cli

                      Guardrail CLI — Ship with confidence. AI-native code scanning, security analysis, and quality gates.

                      • v2.6.0
                      • 12.38
                      • Published

                      oidc-audit

                      Scan AWS IAM roles for OIDC trust policy misconfigurations in GitHub Actions. Free CLI by TrustFix.

                      • v1.0.0
                      • 12.38
                      • Published

                      guardian-config-check

                      Build configuration integrity scanner — detects supply chain compromise indicators in config files

                      • v1.0.0
                      • 12.38
                      • Published

                      guardrails-scanner

                      AI-powered security scanner that automatically fixes vulnerabilities - SQL injection, XSS, secrets exposure, and more. Not just detection, but intelligent autofix before commit.

                      • v1.0.6
                      • 11.61
                      • Published

                      shipguard-cli

                      AI-powered security scanner with Claude API integration and MCP server support

                      • v2.0.0
                      • 11.39
                      • Published

                      devsecops-git-guardian

                      🛡️ Block secrets, misconfigurations, and vulnerabilities before they reach your repository. Real-time security scanning with inline diagnostics.

                        • v1.4.0
                        • 11.24
                        • Published

                        ai-auth-check

                        Audit your auth implementation for security flaws

                        • v1.0.1
                        • 10.96
                        • Published

                        claude-aspm-scan

                        Claude Code skill for Application Security Posture Management — runs Semgrep SAST and optional Shannon pentesting, generates ASPM_SCAN.md reports

                        • v1.0.0
                        • 10.78
                        • Published

                        secret-sweep

                        🔐 Scan your entire git history for accidentally committed secrets. Rotate, fix, and prevent credential exposure.

                        • v1.0.0
                        • 10.35
                        • Published

                        codesentinel-ai

                        AI-powered security scanner for your codebase. Scan for vulnerabilities, get risk scores, auto-report on GitLab MRs.

                        • v1.0.0
                        • 10.06
                        • Published

                        @grepture/cli

                        AI security scanner for developers — Scan for PII, secrets, prompt injection, and unsafe AI SDK usage.

                        • v0.1.0
                        • 9.85
                        • Published

                        @sixthwall/mcp-server

                        MCP server for SixthWall AI code security scanner. Integrates with Claude Code for automatic vulnerability detection with Fix Packs.

                        • v0.1.0
                        • 9.84
                        • Published

                        supamend

                        Pluggable DevSecOps Security Scanner with 10+ scanners and multiple reporting channels

                        • v1.0.0-beta.1
                        • 9.69
                        • Published

                        @yanrix/schemas

                        Yanrix schema definitions — shared types and validation schemas for the Yanrix threat modeling platform. Forthcoming release. Visit yanrix.dev for updates.

                        • v0.0.1
                        • 9.69
                        • Published

                        vibecheck-cli-tool

                        Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

                        • v2.5.2
                        • 9.69
                        • Published

                        dti4q

                        CLI to upload BOM files to Dependency-Track (https://dependencytrack.org/) tool using CI/CD pipelines

                          • v1.0.0
                          • 9.42
                          • Published

                          leaksniff

                          Smell leaks before attackers do.

                          • v0.1.0
                          • 9.40
                          • Published

                          secure-dev-ai

                          Security by design CLI for AI-assisted development - scans projects and guards autonomous agent runs

                          • v0.1.0
                          • 9.33
                          • Published

                          @probex-scan/agent

                          ProbeX Security Agent — 9 scan engines, one command. Local-first DevSecOps scanning with cloud upload.

                          • v1.0.0
                          • 8.70
                          • Published

                          agent-mcp-guard

                          Open-source CLI scanner for risky MCP server and AI agent tool configuration.

                          • v0.4.9
                          • 0.00
                          • Published

                          web-secure-verification

                          Security scanning CLI for React and Next.js — detects CVEs, secrets, license risks, supply chain threats, hydration bugs, RSC boundary violations, and more.

                            • v1.0.1
                            • 0.00
                            • Published

                            @atofinite5/sork-cli

                            Sorkcloud CLI — AI-powered security pipeline for Node.js projects. Scans, triages, fixes, verifies, and supports multiple AI agents (Claude, OpenAI, Codex, Gemini, Mistral, Llama). Works with BYOK or sorkcloud.space-managed keys.

                            • v1.2.1
                            • 0.00
                            • Published