JSPM

Found 191 results for sast

carrot-scan

Command-line tool for detecting vulnerabilities in files and directories.

  • v6.0.1
  • 63.12
  • Published

@soos-io/api-client

This is the SOOS API Client for registered clients leveraging the various integrations to the SOOS platform. Register for a free trial today at https://app.soos.io/register

  • v1.10.6
  • 56.89
  • Published

rnsec

Zero-config security scanner for React Native & Expo apps. Find vulnerabilities with 68 security rules covering Android, iOS, and React Native specific issues.

  • v1.3.0
  • 54.35
  • Published

guardvibe

Security MCP for vibe coding. 390 rules, 36 tools, CLI + doctor. Host security, auth coverage mapping, LLM-powered deep scan (IDOR/business logic), taint analysis, +25 AI-native rules (MCP supply-chain, RAG/vector poisoning, agent loop DoS, public-prefix

  • v3.1.22
  • 52.09
  • Published

@aegis-scan/core

AEGIS core engine — orchestrator, scoring (0-1000), config loader with Zod-strict schema, suppression filter, shared types + utilities. The foundation of the AEGIS security-scanner suite for Next.js + Supabase.

  • v0.18.5
  • 49.23
  • Published

@aegis-scan/scanners

AEGIS scanner registry — 41 built-in regex checkers + 1 AST cross-file taint analyzer + 20 external-tool wrappers (16 SAST/DAST: Semgrep, Gitleaks, Trivy, ZAP, …; +1 passive subdomain-recon: Subfinder; +3 LLM-agent pentest: Strix, PTAI, Pentest-Swarm-AI —

  • v0.18.5
  • 48.07
  • Published

cognium-ai

AI-powered static analysis CLI with LLM-enhanced vulnerability detection

    • v2.7.2
    • 47.16
    • Published

    circle-ir-ai

    LLM-enhanced SAST analysis built on circle-ir

    • v2.7.1
    • 46.96
    • Published

    @aegis-scan/mcp-server

    AEGIS MCP server — exposes scan / findings / score / compliance / fix-suggestion tools to any Model Context Protocol agent (Claude Code, Cursor, Continue, Zed). Five registered tools: aegis_scan, aegis_findings, aegis_score, aegis_compliance, aegis_fix_su

    • v0.18.5
    • 46.48
    • Published

    circle-ir

    High-performance Static Application Security Testing (SAST) library for detecting security vulnerabilities through taint analysis

    • v3.21.0
    • 45.94
    • Published

    @aegis-scan/cli

    AEGIS CLI — paranoid stack-specific security scanner for Next.js + Supabase. 0-1000 score, 42 built-in checkers (+20 external-tool wrappers: 16 SAST/DAST + 1 passive subdomain-recon + 3 LLM-agent pentest frameworks), AST-based cross-file taint analysis, 4

    • v0.18.5
    • 45.38
    • Published

    sast

    Parse CSS, Sass, and SCSS into Unist syntax trees

    • v0.8.1
    • 44.96
    • Published

    @snitchplugin/cli

    Snitch CLI. Unified surface for Snitch security audits AND Snitch: Marketing audits. Runs on your device with your own AI provider key; Snitch's servers never receive your code or your audit findings. PKCE login, scope-gated subcommands.

    • v2.2.0
    • 44.23
    • Published

    @nodesecure/scanner

    A package API to run a static analysis of your module's dependencies.

    • v10.12.0
    • 44.14
    • Published

    @soos-io/soos-sast

    SOOS Static Application Security Testing (SAST) scanning support. Register for a free SOOS trial at https://app.soos.io/register

    • v1.3.4
    • 43.95
    • Published

    vibecipher

    VibeSecurity — Auditoria de segurança para quem cria com IA. Secrets, vulnerabilidades e rotas sem auth.

    • v1.1.26
    • 43.21
    • Published

    foxguard

    A security scanner as fast as a linter, written in Rust. 170+ built-in rules across 10 languages.

    • v0.8.0
    • 43.18
    • Published

    claude-crap

    Deterministic QA plugin for Claude Code — CRAP index, Technical Debt Ratio, tree-sitter AST, SARIF 2.1.0, hooks, and a local Vue dashboard.

    • v0.4.8
    • 42.98
    • Published

    codehere

    A PM for your AI coding agents. Delegate, orchestrate, and audit Claude Code, Codex, Aider, and OpenCode from one local web UI — every AI action traced, every file scored.

    • v0.4.1
    • 42.78
    • Published

    secure-review

    Multi-model security review for AI-generated code. Runs OpenAI, Anthropic, and Google reviewers in parallel and posts findings as PR comments.

    • v1.0.1
    • 42.75
    • Published

    xploitscan

    AI security scanner for vibe-coded apps. Find vulnerabilities before attackers do.

    • v1.1.2
    • 42.24
    • Published

    cognium

    Semantic static analysis engine for detecting security vulnerabilities via taint tracking

    • v1.7.1
    • 42.23
    • Published

    ship-safe

    AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a

    • v9.2.4
    • 42.11
    • Published

    kuzushi

    Kuzushi — security-native AI operating environment

    • v0.20.0
    • 41.87
    • Published

    @kubbisec/aspm

    KubbiSec ASPM — Application Security Posture Management CLI

      • v1.0.33
      • 41.69
      • Published

      getdoorman

      10 security checks. Zero false positives. Ship with confidence.

      • v2.0.1
      • 41.49
      • Published

      ironward

      Security scanning for the vibe coding era. MCP server + CLI that finds secrets, auth bugs, SQL injection, XSS, IDOR, and vulnerable deps — and opens fix PRs. Works in Cursor, Claude Code, and VS Code. Bring your own model (Anthropic, OpenAI, Gemini, Groq,

      • v3.2.0
      • 41.20
      • Published

      @nahisaho/musubix-security

      Security analysis and vulnerability detection for MUSUBIX - Neuro-Symbolic AI Integration with CodeQL-equivalent capabilities

      • v3.8.2
      • 39.43
      • Published

      sec-gate

      Pre-commit security gate for OWASP Top 10 2021 — SAST, SCA and misconfig checks for Node/Express, Go and React codebases

      • v0.2.1
      • 38.27
      • Published

      mythos-agent

      Open-source AI code-review assistant for application security. Flags likely vulnerabilities in source code with reasoning and suggested fixes.

      • v4.2.0
      • 38.12
      • Published

      eduskills-cybersecurity

      Production-grade security hardening skill for Claude Code — AI/vibe-coded projects, OWASP Top 10, zero-trust, red-team, Supabase RLS, compliance (SOC 2, PCI-DSS, GDPR/LGPD)

      • v1.0.7
      • 37.66
      • Published

      @squirex.dev/mcp-server

      SquireX MCP Server — Agentforce Capability Scanner for AI Coding Agents

      • v4.0.1
      • 37.41
      • Published

      codeshield

      The security and reliability linter for JavaScript and TypeScript

      • v0.3.0
      • 37.26
      • Published

      squirex

      Agent Capability Scanner — Salesforce Agentforce, ServiceNow, MuleSoft, and MCP security analysis

        • v4.0.1
        • 36.66
        • Published

        sparrow-sast

        Globstar-compatible static analysis tool for Node.js - A backward-compatible reimplementation of the MIT-licensed Globstar.dev SAST

        • v1.0.1
        • 36.49
        • Published

        @nodesecure/ci

        NodeSecure tool enabling secured continuous delivery

        • v1.7.0
        • 36.48
        • Published

        llm-audit

        Static analysis for LLM-application code. OWASP LLM Top 10 at commit time.

          • v0.0.10
          • 36.36
          • Published

          secure-review-extension

          Run deep static and Docker-based dynamic secure code reviews directly inside VS Code.

          • v1.0.12
          • 36.07
          • Published

          @agentsec/cli

          AI-powered security scanner with 15 scan phases, 10 specialist agents, container/IaC/DAST/taint analysis, and AI-assisted remediation.

          • v0.1.6
          • 35.20
          • Published

          @paretools/security

          MCP server for security scanning — structured Trivy, Semgrep, and Gitleaks findings for AI agents

          • v0.19.1
          • 35.17
          • Published

          codeslick-cli

          CodeSlick CLI tool for pre-commit security scanning — 308 checks across JS, TS, Python, Java, Go

          • v1.6.0
          • 34.87
          • Published

          @tinydarkforge/secgate

          Tiny security gate for CI/CD — orchestrates Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit with a premium HTML report.

          • v0.2.4
          • 34.68
          • Published

          @eastagile/claude-scan

          Anthropic's vulnerability scanning scaffold (Carlini, [un]prompted 2026) — parallel Claude Code security scans per file

          • v1.2.0
          • 34.35
          • Published

          aegistriage

          AI-powered code scanning agent that triages findings and creates Jira tickets

          • v1.0.6
          • 34.35
          • Published

          breach-gate

          OWASP API security scanner with AI-assisted behavioral testing, static analysis, container scanning, and GraphQL probing.

          • v1.2.3
          • 34.10
          • Published

          probus

          Agentic security scanner for code repos — analyst + primary + secondary agent pipeline over OpenRouter / OpenAI / Anthropic models, with a live Ink terminal UI.

          • v0.1.7
          • 34.04
          • Published

          @raknor/aegis

          AEGIS Security Scanner — Governed Cyber Reasoning System

          • v2.3.0
          • 33.91
          • Published

          ferret-scan

          Static security scanner for AI CLI and MCP configurations — detects credential leaks, prompt injection, jailbreaks, and supply chain risks

          • v2.4.0
          • 33.67
          • Published

          agent-security-scanner-mcp

          Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1700+ vulnerability rules with AST & taint analysis, LLM-powered semantic code review, auto-fix. For Claude Code, Cursor, Windsu

          • v4.3.0
          • 33.33
          • Published

          @ruizrica/mako-cli

          Mako Security CLI - scan for vulnerabilities in dependencies, code, and infrastructure

          • v0.1.5
          • 33.13
          • Published

          hookwarden

          Webhook security audit CLI — finds signature-verification bugs in JavaScript, TypeScript, and Python codebases. Local, deterministic, zero-network. Ships rules for Stripe, GitHub, Shopify, Slack, Twilio, and Square; JSON / SARIF 2.1.0 output for CI and Gi

          • v0.2.1
          • 32.76
          • Published

          sentinelflow

          AI agent governance platform — static scanning + runtime interception for Claude Code, Cursor, GitHub Copilot, Codex, LangChain, CrewAI, and Kiro. Blocks dangerous tool calls in real-time.

          • v0.3.1
          • 32.00
          • Published

          @merupatel/reachable

          Local-first vulnerability reachability CLI for JavaScript and TypeScript

          • v1.0.8
          • 31.61
          • Published

          firmis-cli

          The security layer for AI agents — platform-agnostic threat detection with 300+ rules, runtime blocking, and remediation guidance. Continuous protection.

          • v2026.1.4
          • 31.37
          • Published

          codeql-sdk

          CodeQL security audit SDK for clawhub.ai AI skills

          • v1.2.0
          • 31.32
          • Published

          vibesafe-cli

          AI Code Security Auditor — catches vulnerabilities that LLMs introduce and SonarQube misses. Purpose-built for AI-generated code with educational feedback.

          • v1.0.2
          • 31.21
          • Published

          @oh-pen-testing/cli

          Local opensource pen-testing suite. Your code. Your AI. Your terms. `opt` is the CLI entry point.

          • v1.0.2
          • 31.15
          • Published

          @betterqa/security-mcp

          MCP server for AI-powered security scanning - SAST, SCA, DAST, and secrets detection

          • v2.1.3
          • 30.85
          • Published

          vibecheck-ai

          VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

          • v6.0.5
          • 30.84
          • Published

          @offgridsec/kira-lite-mcp

          Kira-Lite MCP Server — Real-time security scanning for AI coding assistants

          • v0.2.1
          • 30.08
          • Published

          crack-code

          AI-powered CLI security auditor that scans codebases for vulnerabilities, explains findings with exact code references, and optionally applies fixes. Provider-agnostic — works with Anthropic, OpenAI, Google, Azure, Vertex AI, and Ollama.

          • v0.3.0
          • 29.98
          • Published

          @flowguard/cli

          AI Agent Security — scan every tool call for secrets, PII, destructive commands, and prompt injection. Runs locally, zero dependencies, no signup required.

          • v0.5.0
          • 29.86
          • Published

          guardrail-cli-tool

          Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

          • v2.5.4
          • 29.57
          • Published

          @guard0/g0

          Background check for AI agents — discover, assess, and test before you ship

          • v2.0.0
          • 29.57
          • Published

          safeweave-mcp

          SafeWeave MCP server — Free SAST, secrets, and dependency scanning for AI code editors. Upgrade to Self-Hosted Pro for all 8 scanners + compliance profiles.

          • v0.4.10
          • 29.55
          • Published

          security-mcp

          AI security MCP server and enforcement gate for Claude Code, Cursor, GitHub Copilot, Codex, Replit, and any MCP-compatible editor. Applies OWASP, MITRE ATT&CK, NIST, Zero Trust, PCI DSS, SOC 2, and ISO 27001.

          • v1.1.4
          • 29.44
          • Published

          security-auditor-agent

          Senior Security Auditor AI agent — performs thorough read-only security analysis of codebases. Identifies vulnerabilities, assesses risk via CVSS scoring, maps compliance gaps, and provides actionable remediation. Built with LangChain, LangGraph, and Groq

            • v1.0.1
            • 29.40
            • Published

            @exploitq/cli

            ExploitQ CLI — SAST, SCA, API security, and secrets scanning for CI/CD pipelines

            • v1.0.3
            • 29.01
            • Published

            bit-security-mcp

            BIT Security Review — MCP server for devs + CLI for CI/CD pipelines. Activates 7 specialized agents (SECRETS, AUTH, DATA, INPUT, DEPS, INCIDENTS, AGENTIC) mapped to OWASP A1–A10, OWASP Agentic AI T1–T15, and CWE.

            • v2.1.1
            • 28.55
            • Published

            @nntndfrk/checkmarx-mcp

            MCP server providing AI coding agents with full programmatic access to the Checkmarx One security platform

            • v0.2.0
            • 28.45
            • Published

            codeslick-mcp-server

            CodeSlick Security Analysis MCP Server - 323 security checks across 5 languages + 17 MCP-specific behavioral checks + AI code detection

            • v1.5.2
            • 28.35
            • Published

            @cybrium-ai/mcp-server

            MCP server for Cybrium security tools — 1,815 rules, 75+ languages. SAST, secrets, IaC, K8s, supply-chain, endpoint posture.

            • v0.2.1
            • 28.31
            • Published

            @smartdec/smartcheck

            SmartCheck is an extensible static analysis tool for discovering vulnerabilities and other code issues in Ethereum smart contracts written in the Solidity programming language.

            • v2.0.1
            • 28.26
            • Published

            asyntax-cli

            Asyntax AI — security-scan your codebase from the terminal

            • v0.3.6
            • 28.15
            • Published

            vulncheck

            AI-powered CLI vulnerability scanner using Gemini

              • v1.0.3
              • 27.94
              • Published

              guardlink

              GuardLink — Security annotations for code. Threat modeling that lives in your codebase.

              • v1.4.2
              • 27.86
              • Published

              codedrift

              Guardrails for AI-assisted development - Detects IDOR, missing input validation, hardcoded secrets, and other critical bugs in AI-generated code

              • v1.2.12
              • 27.63
              • Published

              @ship-safe/cli

              Security scanner for AI-generated code — find vulnerabilities before you ship

              • v1.1.14
              • 27.22
              • Published

              cortexhq

              CortexHQ: Security & Guardrails for AI Code

              • v1.0.2
              • 26.88
              • Published

              @fortify/setup

              Bootstrap and run fcli fortify-setup action in any environment

              • v2.1.3
              • 26.31
              • Published

              vue-security-scanner

              A comprehensive security scanning tool for Vue.js projects with rule-based vulnerability detection

              • v1.7.2
              • 25.89
              • Published

              @darrenjcoxon/vibeguard

              Security-first code scanner for AI-assisted development. Scan your code, get FIXES.md, let AI fix everything.

              • v2.5.0
              • 25.84
              • Published

              @quantumtiger/qv

              Quantum Viper CLI (qv) - Professional AI-Powered Security Analysis

              • v4.0.0
              • 25.76
              • Published

              n8n-nodes-snyk

              A comprehensive n8n community node for Snyk security platform providing 12 resources and 60+ operations for vulnerability management, project monitoring, and security reporting.

              • v1.0.0
              • 25.60
              • Published

              secure-scan

              Herramienta SAST (Análisis Estático de Seguridad) para detectar vulnerabilidades y código malicioso.

              • v1.2.5
              • 25.57
              • Published

              claude-audit

              AI-powered codebase auditor — security, quality, performance, architecture & more

              • v0.1.1
              • 25.31
              • Published

              siteshadow

              SiteShadow CLI — 2,021 security checks, 249 CWEs, 100% OWASP 2025 coverage.

              • v0.1.0
              • 24.82
              • Published

              mcpeek

              Source-code-level security scanner for MCP server implementations

                • v1.0.0
                • 24.82
                • Published

                piilex

                PII Lexical Analyzer -- Detect PII in source code and map to GDPR/CCPA regulatory frameworks

                • v0.1.0
                • 23.52
                • Published

                agent-security-policies

                Portable, standards-backed security policies for any AI coding agent. One command to install OWASP, CWE, NIST rules + security skills.

                • v1.5.7
                • 23.47
                • Published

                @vibecheckai/cli

                Vibecheck CLI - Ship with confidence. One verdict: SHIP | WARN | BLOCK.

                • v4.0.2
                • 23.45
                • Published

                aura-security

                AI-powered security scanner with 9-agent swarm. Detect secrets, vulnerabilities, attack paths. CLI, API, or cloud dashboard at app.aurasecurity.io

                • v1.0.3
                • 23.22
                • Published

                @aiclude/security-skill

                AICLUDE Security Vulnerability Scanner - Claude Code Skill for querying the AICLUDE scan database

                • v3.0.0
                • 23.19
                • Published

                blackduck-polaris-mcp-server

                Feature-rich MCP server for Black Duck Polaris — trigger SAST/SCA/DAST scans, query findings, generate reports (SBOM, SPDX, CycloneDX), manage policies, triage issues, and more. Works with Claude Code, Claude Desktop, GitHub Copilot, Cursor, and any MCP-c

                  • v0.3.1
                  • 23.15
                  • Published

                  titanshield

                  TitanShieldAI CLI — AI-powered security scanner for your codebase. Zero config. Under 2 minutes.

                  • v0.6.4
                  • 22.77
                  • Published

                  ngx-security-audit

                  The most comprehensive Angular security auditing tool. 150+ rules, 10 scan types (OWASP, API security, performance, accessibility, dependency audit, hacking, complexity, code quality). Auto-fix suggestions, HTML dashboard, SVG badge generation, SARIF expo

                  • v2.0.1
                  • 22.63
                  • Published

                  @mcp-guard/core

                  Security scanning engine for Model Context Protocol (MCP) servers. Detects hardcoded secrets, command injection, SSRF, auth misconfig, and compliance gaps.

                  • v2.1.0
                  • 22.56
                  • Published

                  @mtgibbs/blackduck-polaris-mcp

                  MCP server for querying Black Duck Polaris security vulnerabilities, issues, and scan results

                  • v1.0.2
                  • 22.42
                  • Published

                  @emisso/security

                  AI-powered security scanner for codebases and pull requests — SAST, secrets, dependencies, threat modeling

                  • v0.1.0
                  • 21.84
                  • Published

                  @emisso/security-cli

                  CLI for AI-powered security scanning of codebases and pull requests

                  • v0.1.0
                  • 21.84
                  • Published

                  @breach-kit/agent

                  BreachKit — AI security testing agent. MCP server that turns your coding agent into a pen tester. DAST, SAST, and SCA via Playwright.

                  • v1.0.3
                  • 21.83
                  • Published

                  audit-code

                  AUDIT CLI binaries with automatic platform download and verification.

                  • v0.2.0
                  • 21.75
                  • Published

                  @oculum/cli

                  AI-native security scanner CLI for detecting vulnerabilities in AI-generated code, BYOK patterns, and modern web applications

                  • v1.0.21
                  • 21.55
                  • Published

                  guardrail-cli

                  Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

                  • v2.5.4
                  • 21.45
                  • Published

                  @aiclude/security-mcp

                  AICLUDE Security Vulnerability Scanner - MCP Server for querying vulnerability scan results

                  • v3.0.0
                  • 21.44
                  • Published

                  @empowered-humanity/agent-security

                  Security scanner for AI agent architectures - 220+ detection patterns and 5 runtime guard modules for prompt injection, SSRF, path traversal, credential exposure, MCP security, and OWASP ASI vulnerabilities

                  • v2.0.0
                  • 21.37
                  • Published

                  @sparrowai/sparrow-mcp

                  A Model Context Protocol (MCP) server that automatically analyzes security vulnerabilities in your code and generates secure code alternatives. This server integrates with Cursor IDE to provide real-time security analysis and secure code generation capabi

                    • v1.1.14
                    • 20.53
                    • Published

                    @vexlit/cli

                    VEXLIT CLI — AI-powered code security vulnerability scanner

                    • v0.1.5
                    • 20.42
                    • Published

                    vbguard

                    Security scanner for AI-generated code. Catches what traditional scanners miss.

                      • v1.0.2
                      • 19.84
                      • Published

                      @nohacklabs/mcp-server

                      MCP server for NoHack security scanning API - query vulnerabilities, secrets, scans, and repo configs

                      • v1.0.3
                      • 19.68
                      • Published

                      prooflayer-agent-security

                      Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1700+ vulnerability rules with AST & taint analysis, LLM-powered semantic code review, auto-fix. For Claude Code, Cursor, Windsu

                      • v4.0.0
                      • 19.37
                      • Published

                      @codethreat/appsec-cli

                      CodeThreat AppSec CLI for CI/CD integration and automated security scanning

                        • v1.13.0
                        • 19.24
                        • Published

                        sast-scan

                        A lightweight, extensible Static Application Security Testing (SAST) tool for JavaScript. Detects vulnerabilities like XSS, SQL injection, hardcoded secrets, prototype pollution, and more — with CWE references, severity ratings, and context-aware reportin

                        • v2.1.0
                        • 18.99
                        • Published

                        anais-apk-forensic

                        Comprehensive APK security analysis and forensic investigation tool for Android applications

                        • v1.1.1
                        • 18.59
                        • Published

                        fixyoursecret

                        CLI tool to detect leaked secrets, frontend exposure, and generate safe fixes.

                        • v0.4.3
                        • 17.78
                        • Published

                        finsec-scan

                        Security Scanner for Financial Applications - CLI tool for detecting vulnerabilities, secrets, and security issues in fintech codebases

                        • v1.1.0
                        • 17.70
                        • Published

                        openseccli

                        The open-source security CLI hub — query, enrich, automate.

                        • v1.0.0
                        • 16.97
                        • Published

                        venom-pentest

                        Venom — Autonomous AI pentester for developers. Find exploits AND fix them.

                        • v1.2.1
                        • 16.85
                        • Published

                        claudesec

                        DevSecOps toolkit for AI-assisted secure development — security scanner, ISMS dashboard, asset management

                        • v0.6.1
                        • 16.80
                        • Published

                        uncloak-security

                        Security scanner for AI-generated and vibe-coded projects. Detects secrets, injection attacks, weak crypto, backdoors, and more.

                        • v2.3.1
                        • 16.58
                        • Published

                        @appknox/mcp-server

                        Official Model Context Protocol (MCP) server for Appknox - enables AI assistants to perform mobile application security testing

                        • v1.0.1
                        • 16.19
                        • Published

                        opensecurity

                        Open-source CLI for scanning repositories for security risks across code, infra, and dependencies.

                        • v0.3.0
                        • 16.06
                        • Published

                        @guardrailai/cli

                        Guardrail CLI — Ship with confidence. AI-native code scanning, security analysis, and quality gates.

                        • v2.6.0
                        • 15.88
                        • Published

                        glancevibe

                        GlanceVibe CLI - Security vulnerability scanner for JavaScript/TypeScript

                          • v0.2.2
                          • 15.06
                          • Published

                          @prooflayer/security-scanner

                          Lightweight, zero-Python security scanner MCP server for AI coding agents. Fast install (~5s), 1700+ vulnerability rules with pure JavaScript regex engine, 4.3M+ package hallucination detection. For Claude Code, Cursor, Windsurf, Cline.

                          • v1.0.0
                          • 14.83
                          • Published

                          gemini-bug-hunter

                          AI-Powered Security Vulnerability Hunter using Gemini 2.5 Flash

                          • v1.2.0
                          • 14.40
                          • Published

                          launchcrate

                          AI-powered feature scaffolding for Next.js. Vibe code safely.

                          • v0.2.0
                          • 14.35
                          • Published

                          @onamfc/security-scanner

                          Enterprise-grade CLI security scanner for detecting secrets and vulnerabilities in codebases

                          • v1.0.0
                          • 14.34
                          • Published

                          @vexlit/core

                          VEXLIT core analysis engine — AI-powered code security vulnerability scanner

                          • v0.1.1
                          • 13.70
                          • Published

                          @iflow-mcp/sinewaveai-agent-security-scanner-mcp

                          Security scanner MCP server for AI coding agents. Prompt injection firewall, package hallucination detection (4.3M+ packages), 1000+ vulnerability rules with AST & taint analysis, auto-fix. For Claude Code, Cursor, Windsurf, Cline, OpenClaw.

                          • v3.18.1
                          • 13.64
                          • Published

                          @firmislabs/firmis

                          AI agent security platform — scan, fix, monitor, and pentest MCP servers, Claude skills, Codex plugins, Cursor extensions, and 5 more platforms. 227 rules across 17 threat categories.

                          • v2.0.0
                          • 13.47
                          • Published

                          @vibecheckdev/vibecheckai

                          VibeCheck Ultimate CLI — Ship with confidence. 65+ commands merged from 4 codebases: kernel infrastructure, ISL verification, Reality Mode, Agent Firewall, MCP Server.

                          • v6.0.6
                          • 13.19
                          • Published

                          mcp-security-auditor

                          Security scanner for MCP (Model Context Protocol) servers. Detect vulnerabilities, secrets, injection risks, and misconfigurations before deployment.

                          • v1.0.2
                          • 13.15
                          • Published

                          vibecheckdev

                          AI security scanner for vibe-coded apps. Find vulnerabilities before attackers do.

                          • v0.4.0
                          • 13.09
                          • Published

                          @bhupesh123/security

                          Security vulnerability analysis microservice for GitHub repositories

                            • v1.0.1
                            • 13.07
                            • Published

                            skscan

                            Security scanner for AI agent skills — detect secrets, prompt injections, and dangerous code

                            • v0.1.1
                            • 13.04
                            • Published

                            guardscan

                            GuardScan - Privacy-first AI Code Review CLI with comprehensive security scanning

                            • v1.0.5
                            • 12.90
                            • Published

                            @devsecurex/cli

                            DevSecureX CLI - Advanced security scanning tool for developers. Detect vulnerabilities across 20+ programming languages with comprehensive SAST, dependency analysis, secrets detection, and compliance reporting. Integrates seamlessly with CI/CD pipelines

                            • v0.3.0
                            • 12.73
                            • Published

                            riplock-cli

                            Security scanner with AST taint tracking — we're watching your back so you can let it rip

                            • v2.0.0
                            • 12.60
                            • Published

                            @prooflayer/scanner-lite

                            Lightweight MCP security scanner for AI coding agents. 400+ YAML rules, tool-poisoning detection, prompt injection scanning, package hallucination checks, auto-fix generation, and optional LLM deep audit. MIT licensed, fully offline-capable.

                            • v1.0.0
                            • 12.43
                            • Published

                            devrail

                            Security & Quality Guardrails - Adoption-first developer discipline. Block new issues, accept existing ones with baseline mode.

                            • v0.1.0
                            • 12.40
                            • Published

                            @szcn/sentinelreview

                            AI-powered code review — security (OWASP Top 10), code quality, standards enforcement, and custom rules. 6 providers (Ollama free/local, Gemini, Groq, DeepSeek, OpenAI, Anthropic). MCP server for Cursor, Windsurf, VS Code, Claude Desktop + CLI + Node API.

                              • v1.0.1
                              • 12.37
                              • Published

                              @grepture/cli

                              AI security scanner for developers — Scan for PII, secrets, prompt injection, and unsafe AI SDK usage.

                              • v0.1.0
                              • 12.10
                              • Published

                              @darrenjcoxon/vibeguard-replit

                              Vibeguard for Replit - Security scanner with pre-configured Nix environment. All tools included.

                              • v2.2.0
                              • 11.83
                              • Published

                              vbgaurd

                              Security scanner for AI-generated code. Catches what traditional scanners miss — hardcoded secrets, dangerous defaults, exposed keys, and more.

                                • v0.1.0
                                • 11.69
                                • Published

                                ghostpatch

                                AI-powered security vulnerability scanner that runs locally via npm with zero infrastructure. Uses free HuggingFace models by default.

                                • v1.0.1
                                • 11.31
                                • Published

                                codesentinel-ai

                                AI-powered security scanner for your codebase. Scan for vulnerabilities, get risk scores, auto-report on GitLab MRs.

                                • v1.0.0
                                • 11.31
                                • Published

                                kern.open

                                AI-first security orchestration CLI: secrets, SAST, and SCA in one command

                                  • v1.0.0
                                  • 10.76
                                  • Published

                                  securedx

                                  Graduated security gates for DevSecOps pipelines - A developer-centric approach to security enforcement with configurable severity thresholds and productivity analytics

                                    • v2.0.1
                                    • 10.33
                                    • Published

                                    node-protect

                                    Security scanner for Node.js projects checking for OWASP Top 10 risks

                                      • v1.1.0
                                      • 10.19
                                      • Published

                                      risk-audit-mcp

                                      Risk Audit MCP server that scans projects for security issues (XSS, injections, etc.)

                                      • v0.1.1
                                      • 10.01
                                      • Published

                                      qryon

                                      Qryon - Ultra-fast code intelligence and security analyzer for polyglot projects

                                      • v0.20.1
                                      • 9.66
                                      • Published

                                      ghostcheck

                                      AI code vulnerability scanner — catches hallucinated packages, phantom APIs, and insecure patterns before you commit. Zero-config, offline, under 2 seconds.

                                      • v0.1.0
                                      • 9.63
                                      • Published

                                      claude-aspm-scan

                                      Claude Code skill for Application Security Posture Management — runs Semgrep SAST and optional Shannon pentesting, generates ASPM_SCAN.md reports

                                      • v1.0.0
                                      • 9.57
                                      • Published

                                      @raj-dev/guardrail

                                      A lightweight, offline-first security scanner for npm projects.

                                      • v1.0.0
                                      • 9.32
                                      • Published

                                      vibecheck-cli-tool

                                      Guardrail CLI - Enterprise security scanning with interactive menu, arrow navigation, and auto-installation

                                      • v2.5.2
                                      • 8.95
                                      • Published

                                      x2y-guardian

                                      A command-line tool for cross-language dependency vulnerability scanning and analysis by x2y dev tools.

                                      • v1.0.2
                                      • 8.95
                                      • Published

                                      cyrook-cli

                                      Official CLI for CyRook - Developer-first web & API security scanning platform

                                      • v1.0.1
                                      • 8.71
                                      • Published

                                      @probex-scan/agent

                                      ProbeX Security Agent — 9 scan engines, one command. Local-first DevSecOps scanning with cloud upload.

                                      • v1.0.0
                                      • 8.71
                                      • Published

                                      react-native-lupin

                                      Fast, beautiful CLI security scanner for React Native and Expo bundles. Detects API keys, secrets, and 60+ mobile security vulnerabilities.

                                      • v1.3.0
                                      • 8.40
                                      • Published

                                      vibesec

                                      Security scanner for AI-generated code - detects vulnerabilities in vibe-coded projects

                                      • v0.1.0
                                      • 8.32
                                      • Published

                                      supamend

                                      Pluggable DevSecOps Security Scanner with 10+ scanners and multiple reporting channels

                                      • v1.0.0-beta.1
                                      • 8.25
                                      • Published

                                      claudescan

                                      ClaudeScan Security Scanner CLI

                                        • v1.0.0
                                        • 8.25
                                        • Published

                                        vulnsink

                                        SAST + LLM Security Scanner that filters false positives and auto-fixes issues

                                        • v0.1.0
                                        • 8.03
                                        • Published

                                        vulnburn

                                        A security scanner with an attitude

                                          • v1.0.3
                                          • 7.36
                                          • Published

                                          sarif2gl

                                          deliver SAST results to gitlab merge request discussions

                                          • v1.0.4
                                          • 7.26
                                          • Published

                                          cszone38

                                          Static analysis CLI for C# codebases. Detects AI-generated code, hardcoded secrets, and quality issues.

                                            • v0.1.1
                                            • 0.00
                                            • Published

                                            @xclusive/vibeshield

                                            Hybrid (AST + LLM) security scanner with multi-provider support for OpenAI, Anthropic, Google Gemini, and local Ollama

                                            • v1.1.0
                                            • 0.00
                                            • Published

                                            compliancemaxx

                                            Multi-framework compliance orchestrator (OSS-license, OWASP ASVS, ISO 27001, SOC 2, GDPR) for repo and CI/CD.

                                            • v2.0.2
                                            • 0.00
                                            • Published

                                            @funkymed/basile

                                            BASILE CLI — multi-stack audit runner

                                            • v0.0.5
                                            • 0.00
                                            • Published

                                            hzsec-cli

                                            Local-first security scanner. Finds secrets, misconfigs, and unsafe code patterns. Runs in CI. Free, MIT-licensed, no telemetry.

                                            • v1.0.0
                                            • 0.00
                                            • Published

                                            securascan

                                            AI-powered security scanner CLI — scans codebases for OWASP Top 10 vulnerabilities using LLMs

                                            • v1.0.0
                                            • 0.00
                                            • Published