JSPM

Found 130 results for vulnerability-scanner

carrot-scan

Command-line tool for detecting vulnerabilities in files and directories.

  • v6.0.1
  • 65.20
  • Published

bun-scan

Vulnerability scanner for Bun projects

  • v1.1.2
  • 47.00
  • Published

devcompass

Dependency health checker with ecosystem intelligence, unified interactive dashboard with 5 dynamic layouts (Tree/Force/Radial/Conflict/Analytics), historical tracking with SQLite, snapshot comparison, timeline visualization, modular CSS/JS architecture,

  • v3.2.4
  • 46.60
  • Published

vibecipher

VibeSecurity — Auditoria de segurança para quem cria com IA. Secrets, vulnerabilidades e rotas sem auth.

  • v1.1.26
  • 44.50
  • Published

ship-safe

AI-powered multi-agent security platform. 23 agents scan 80+ attack classes including AI integration supply chain (Vercel-class attacks), Hermes Agent deployments (ASI-01–ASI-10), tool registry poisoning, function-call injection, skill permission drift, a

  • v9.2.4
  • 43.50
  • Published

depscope-mcp

Package Intelligence MCP server for AI agents. Stops hallucinated/malicious package installs across 19 ecosystems (npm, PyPI, Cargo, Go, Maven, NuGet, RubyGems, Composer, Pub, Hex, Swift, CocoaPods, CPAN, Hackage, CRAN, Conda, Homebrew, JSR, Julia). 22 to

  • v0.9.0
  • 41.87
  • Published

@spys/mcp

⚠️ Pre-release — wait for 1.0.0 before relying on this. Currently under active development; APIs and behaviour may change without notice. SPYS MCP client — local stdio bridge + reverse tunnel for AI-driven pentest tools (Claude Code, Cursor, etc).

  • v0.9.5
  • 39.46
  • Published

codeshield

The security and reliability linter for JavaScript and TypeScript

  • v0.3.0
  • 39.18
  • Published

@netxeo/security-skill

Enterprise-grade AI security skill for any codebase — covers CWE Top 25, OWASP Top 10, ASVS Level 1-3

  • v1.3.0
  • 36.46
  • Published

@eastagile/claude-scan

Anthropic's vulnerability scanning scaffold (Carlini, [un]prompted 2026) — parallel Claude Code security scans per file

  • v1.2.0
  • 36.19
  • Published

codeslick-cli

CodeSlick CLI tool for pre-commit security scanning — 308 checks across JS, TS, Python, Java, Go

  • v1.6.0
  • 35.91
  • Published

modality-safe

Advanced security scanner that detects API key leaks and sensitive information in source code. Scans TypeScript, JavaScript, Markdown, and configuration files for AWS keys, OpenAI tokens, GitHub/GitLab PATs, Slack/Discord tokens, JWT tokens, and other cre

  • v0.4.1
  • 35.69
  • Published

hono-honeypot

Hono.js security middleware. Honeypot path blocker that stops vulnerability scanners (nuclei, nikto, sqlmap, dirbuster), bot crawlers, and brute-force probes. Mini WAF with optional IP strike and ban. Zero dependencies. Cloudflare Workers, Bun, Deno, Node

  • v1.3.3
  • 35.57
  • Published

probus

Agentic security scanner for code repos — analyst + primary + secondary agent pipeline over OpenRouter / OpenAI / Anthropic models, with a live Ink terminal UI.

  • v0.1.7
  • 35.49
  • Published

ferret-scan

Static security scanner for AI CLI and MCP configurations — detects credential leaks, prompt injection, jailbreaks, and supply chain risks

  • v2.4.0
  • 35.48
  • Published

breach-gate

OWASP API security scanner with AI-assisted behavioral testing, static analysis, container scanning, and GraphQL probing.

  • v1.2.3
  • 35.23
  • Published

swarmhack-cli

SwarmHack - Neural swarm-based penetration testing framework

  • v2.3.1
  • 34.35
  • Published

mcp-scan

Open-source security scanner for Model Context Protocol (MCP) servers. Audits Claude Desktop, VS Code, Cursor, Windsurf, and 16+ AI tools for secrets, prompt injection, supply-chain risks, and 17+ security checks.

  • v2.0.2
  • 34.18
  • Published

@oh-pen-testing/cli

Local opensource pen-testing suite. Your code. Your AI. Your terms. `opt` is the CLI entry point.

  • v1.0.2
  • 33.13
  • Published

@gsknnft/skill-safe

Zero-dependency skill sanitizer — scans agent skill markdown for prompt injection, jailbreaks, data exfiltration, and other red flags before installation.

  • v0.3.0
  • 32.60
  • Published

@merupatel/reachable

Local-first vulnerability reachability CLI for JavaScript and TypeScript

  • v1.0.8
  • 32.55
  • Published

@bun-security-scanner/npm

npm registry vulnerability scanner for Bun projects using GitHub Advisory Database

  • v1.0.0
  • 32.29
  • Published

@betterqa/security-mcp

MCP server for AI-powered security scanning - SAST, SCA, DAST, and secrets detection

  • v2.1.3
  • 31.77
  • Published

@vettiq/mcp-server

VettIQ MCP server — security scanning for AI-generated code, callable from Cursor, Claude Code, and any MCP-compatible agent.

  • v1.2.0
  • 31.69
  • Published

crack-code

AI-powered CLI security auditor that scans codebases for vulnerabilities, explains findings with exact code references, and optionally applies fixes. Provider-agnostic — works with Anthropic, OpenAI, Google, Azure, Vertex AI, and Ollama.

  • v0.3.0
  • 31.59
  • Published

security-reporter

Security and quality reporter for Node.js projects. Scans for vulnerabilities, secrets, outdated dependencies, and generates comprehensive reports (console, Markdown, PDF).

  • v1.0.9
  • 31.48
  • Published

@finktech/mcp-verify

Enterprise-grade security validation and testing tool for MCP servers (Model Context Protocol)

  • v1.0.2
  • 30.66
  • Published

verification-layer

Open-source HIPAA compliance scanner for healthcare code. 140+ rules, 5 HIPAA categories. CLI + CI/CD + VS Code.

  • v0.24.4
  • 30.55
  • Published

asyntax-cli

Asyntax AI — security-scan your codebase from the terminal

  • v0.3.6
  • 29.60
  • Published

bit-security-mcp

BIT Security Review — MCP server for devs + CLI for CI/CD pipelines. Activates 7 specialized agents (SECRETS, AUTH, DATA, INPUT, DEPS, INCIDENTS, AGENTIC) mapped to OWASP A1–A10, OWASP Agentic AI T1–T15, and CWE.

  • v2.1.1
  • 29.40
  • Published

dev-optimizer

Analyze and optimize Docker images, npm packages, and CI/CD pipelines. Find unused dependencies, security issues, and cost savings in minutes.

  • v0.1.17
  • 28.82
  • Published

@tihn/bun-guard

A security scanner for Bun's package manager

  • v1.4.1
  • 28.82
  • Published

aico-ai

AI-powered code quality platform with team rules, security scanning, and CI/CD integration. Your complete code gatekeeper.

  • v1.1.6
  • 28.46
  • Published

osv-ui

A beautiful, zero-config visual CVE dashboard for npm, Python, Go, and Rust. Run 'npx osv-ui' to scan or 'npx osv-ui -d' to auto-discover services. Repo: https://github.com/toan203/osv-ui

  • v1.1.6
  • 28.30
  • Published

pinocscan

Security scanner for agent skill files - detects command injection, unsafe file operations, hardcoded secrets, and code injection risks

  • v1.3.2
  • 27.82
  • Published

hardhat-contractscan

Hardhat plugin for ContractScan — AI-powered smart contract vulnerability scanner

  • v0.1.1
  • 27.65
  • Published

@quantumtiger/qv

Quantum Viper CLI (qv) - Professional AI-Powered Security Analysis

  • v4.0.0
  • 27.40
  • Published

nsauditor-ai-agent-skill

AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows.

  • v0.1.10
  • 27.03
  • Published

detectzestack-mcp

MCP server for DetectZeStack — detect tech stacks, security headers, SSL certificates, DNS records, and vulnerabilities for any website

  • v1.0.0
  • 26.61
  • Published

@oalacea/guardian

AI-powered security review plugin for pentesting web applications with NestJS, Rust, Vite support and DDoS/Stress testing - Added BeEzz_QL for GraphQL

  • v0.6.9
  • 26.61
  • Published

secure-scan

Herramienta SAST (Análisis Estático de Seguridad) para detectar vulnerabilidades y código malicioso.

  • v1.2.5
  • 26.52
  • Published

@introspect-cli/introspect

Your code, deeply analyzed. Multi-language code scanner with 432 detection rules, git intelligence, live server security scanning, and AI-powered insights.

  • v0.1.0
  • 26.31
  • Published

valyrian-edge

Autonomous AI Penetration Testing Platform for LLM-powered applications

  • v1.0.0
  • 26.04
  • Published

@piiiico/mcpaudit

Static vulnerability scanner for MCP (Model Context Protocol) servers — detects shell injection, path traversal, SSRF, SQL injection, and more

  • v1.0.0
  • 25.16
  • Published

smartguard-mcp

SmartGuard MCP Server - AI-powered smart contract security audit tools for Claude Code, Cursor, and AI coding agents. Detect reentrancy, access control, and quantum vulnerabilities.

  • v0.1.1
  • 25.13
  • Published

shai-hulud-inspector

Security scanner that checks npm dependencies for Shai Hulud vulnerable packages. 100% offline, zero data collection, zero telemetry. Scans all dependencies against 689+ known compromised packages.

  • v1.0.6
  • 24.95
  • Published

vigile-mcp

MCP server for Vigile AI Security — query trust scores for MCP servers and agent skills from within Claude Code, Cursor, and other AI agents

  • v0.1.10
  • 24.45
  • Published

ai-testing-suite

LangGraph Multi-Agent Automated Testing Suite for Node.js/TypeScript — 8 AI agents that analyze, test, review, secure & document your project. OWASP Top 10, Zero-Day scanning, 100+ vulnerability patterns.

  • v1.3.0
  • 24.43
  • Published

@mcp-guard/core

Security scanning engine for Model Context Protocol (MCP) servers. Detects hardcoded secrets, command injection, SSRF, auth misconfig, and compliance gaps.

  • v2.1.0
  • 23.77
  • Published

@finishkit/mcp

MCP server for FinishKit. Production readiness scanner for AI-built apps. Enables AI agents in Claude, Cursor, Windsurf, and VS Code to check if code is ready to ship.

  • v0.3.3
  • 23.57
  • Published

@empowered-humanity/agent-security

Security scanner for AI agent architectures - 220+ detection patterns and 5 runtime guard modules for prompt injection, SSRF, path traversal, credential exposure, MCP security, and OWASP ASI vulnerabilities

  • v2.0.0
  • 22.17
  • Published

depmender

Comprehensive CLI tool for dependency management - unified 'depmender fix' command handles all operations: scan, fix, install-missing, remove-unused, update-deps, dedupe, sync, resolve, and more. Supports npm, yarn, pnpm with security audits and real-time

  • v2.3.4
  • 22.08
  • Published

vineguard-mcp

VineGuard MCP Server v2.1 - Intelligent QA Workflow System with advanced test generation for Jest/RTL, Cypress, and Playwright. Features smart project analysis, progressive testing strategies, and comprehensive quality patterns for React/Vue/Angular proje

  • v2.1.12
  • 21.85
  • Published

rlm-analyzer

AI-powered code analysis using Recursive Language Models (RLMs). Analyze entire codebases 100x beyond context limits with deep architecture, security, and refactoring analysis. Supports Gemini and Amazon Bedrock.

  • v1.7.1
  • 21.77
  • Published

vulcn

Modern, fast penetration testing CLI — record browser interactions once, replay with security payloads, and find vulnerabilities like XSS and SQLi automatically. A lightweight, pluggable alternative to legacy security scanners.

  • v0.9.3
  • 21.77
  • Published

@mcp-guard/cli

Command-line interface for mcp-guard: scan, fix, and monitor Model Context Protocol (MCP) server configs for security issues.

  • v1.1.0
  • 21.76
  • Published

mcp-cve-intelligence-server-lite

Lite Model Context Protocol server for comprehensive CVE intelligence gathering with multi-source exploit discovery, designed for security professionals and cybersecurity researchers

  • v0.0.8
  • 21.48
  • Published

crowbar-security

autonomous black-box web penetration testing. give it a URL, it finds everything exploitable.

  • v0.1.3
  • 21.21
  • Published

jaku.sh

JAKU (呪) — Autonomous Security & Quality Intelligence Agent for vibe-coded apps. XSS, SQLi, prompt injection, QA testing, and attack chain correlation in one command.

  • v1.0.3
  • 21.09
  • Published

@vulcn/engine

Fast, modern security testing engine — record browser sessions, replay with attack payloads, and detect vulnerabilities automatically. Pluggable driver and detection system for web application penetration testing.

  • v0.9.3
  • 20.62
  • Published

@dreamhorizonorg/sentinel

Open-source, zero-dependency tool that blocks compromised packages BEFORE download. Built to counter supply chain and credential theft attacks like Shai-Hulud.

  • v1.0.0
  • 20.29
  • Published

solaudit-cli

Solidity smart contract security auditor CLI - Detect vulnerabilities, reentrancy, overflow, and common issues.

  • v1.0.0
  • 20.11
  • Published

@proug/mcp-cve-intelligence-server-lite

Lite Model Context Protocol server for comprehensive CVE intelligence gathering with multi-source exploit discovery, designed for security professionals and cybersecurity researchers

  • v0.1.1
  • 20.01
  • Published

sast-scan

A lightweight, extensible Static Application Security Testing (SAST) tool for JavaScript. Detects vulnerabilities like XSS, SQL injection, hardcoded secrets, prototype pollution, and more — with CWE references, severity ratings, and context-aware reportin

  • v2.1.0
  • 19.55
  • Published

gc-nuclei-mcp

Model Context Protocol (MCP) server for interacting with Nuclei vulnerability scanner

  • v1.1.5
  • 18.99
  • Published

nikto-mcp

A secure MCP (Model Context Protocol) server that enables AI agents to interact with Nikto web server scanner

  • v0.7.1
  • 18.63
  • Published

quantumguard-mcp

QuantumGuard MCP Server - Post-quantum cryptography security tools for AI coding agents. Scan for quantum vulnerabilities, get migration templates, check NIST compliance.

  • v0.1.1
  • 17.99
  • Published

venom-pentest

Venom — Autonomous AI pentester for developers. Find exploits AND fix them.

  • v1.2.1
  • 17.72
  • Published

openseccli

The open-source security CLI hub — query, enrich, automate.

  • v1.0.0
  • 17.70
  • Published

@depsshield/mcp-server

Model Context Protocol server for DepsShield - Real-time dependency security scoring for AI agents

  • v0.3.1
  • 17.53
  • Published

electron-channel-doctor

Advanced Script Doctor: Surgical code cleanup + Electron IPC channel management + Security vulnerability detection. Remove unused code, fix missing channels, and detect IPC security issues with AI-powered analysis.

  • v2.4.0
  • 17.50
  • Published

mcp-server-security-audit

MCP server for MetalTorque Security Audit — gives AI agents the ability to scan websites for security vulnerabilities.

  • v1.0.3
  • 17.41
  • Published

mcp-cve-intelligence-server-lite-test

Lite Model Context Protocol server for comprehensive CVE intelligence gathering with multi-source exploit discovery, designed for security professionals and cybersecurity researchers - Alpha Release

  • v0.1.0-alpha.0-20250803T114838
  • 17.36
  • Published

@devdonzo/warden

Autonomous SRE & Security Orchestration Agent - The Warden of your Codebase

  • v1.3.0
  • 17.29
  • Published

@feardread/fear-ai-agent

AI-powered personal development and network security agent with API testing and CVE database integration

  • v2.0.2
  • 16.90
  • Published

vulnripper

Vulnerability Intelligence platform searching for vulnerabilities, exploits, and malicious packages with network scanning and agent-based discovery.

  • v1.1.0
  • 16.29
  • Published

clyrolabs-vibesecurity

Servidor MCP (Model Context Protocol) com Zero Trust para análise de segurança com Trivy. Protege workspaces contra Path Traversal, executa scans de vulnerabilidade e gera patches de correção.

  • v2.0.0
  • 16.04
  • Published

vibe-checker

AI-powered codebase vulnerability scanner

  • v1.0.3
  • 15.78
  • Published

vaultace-cli

AI-powered security scanner that detects vulnerabilities in AI-generated code. Proactive scanning, autonomous fixing, and emergency response for modern development teams.

  • v1.0.3
  • 15.53
  • Published

v7-scanner

Lightning-fast, zero-dependency static analysis tool for detecting security vulnerabilities, SQL injections, XSS risks, and common code bugs.

  • v2.0.0
  • 15.23
  • Published

troj3n

🛡️ Antivirus for Node.js projects - Scan for infected files and malicious/vulnerable packages with real-time protection

  • v0.0.12
  • 14.81
  • Published

@feardread/security-agent

Advanced Security Testing and Analysis Framework with AI capabilities

  • v2.4.4
  • 14.57
  • Published

testpal-ai

TESTPAL v7.1 - AI-Powered Testing Agent with Hardened Security, Git History Verification, Multi-Factor Confidence, 30+ Secret Patterns (HuggingFace, Anthropic, AWS, etc.), Framework-Aware Analysis, 95%+ accuracy. Created by Akash S

  • v7.1.2
  • 14.40
  • Published

sql-query-safety-checker

🛡️ Comprehensive TypeScript library for SQL query security analysis with injection detection, risk assessment, and Express middleware integration

  • v1.1.9
  • 14.18
  • Published

nicefox-secu

Zero-config AI-powered security review for web developers

  • v1.4.1
  • 14.12
  • Published

npm-audit-guard

CLI tool for npm security audit with blacklist functionality and progress bar

  • v1.2.1
  • 13.81
  • Published

guardscan

GuardScan - Privacy-first AI Code Review CLI with comprehensive security scanning

  • v1.0.5
  • 13.45
  • Published

agent-wars

Multi-agent security testing tool - Red Team vs Blue Team with Green Team referee

    • v1.0.1
    • 13.39
    • Published

    @devsecurex/cli

    DevSecureX CLI - Advanced security scanning tool for developers. Detect vulnerabilities across 20+ programming languages with comprehensive SAST, dependency analysis, secrets detection, and compliance reporting. Integrates seamlessly with CI/CD pipelines

    • v0.3.0
    • 13.11
    • Published

    mcp-security-linter

    MCP-SecLint: Static analysis tool for detecting vulnerabilities in MCP server implementations

    • v1.6.1
    • 12.87
    • Published

    hardcoded-api-key-detector

    Comprehensive security tool to detect hardcoded API keys, tokens, and sensitive credentials in your codebase with 245+ detection patterns, entropy analysis, and baseline filtering

    • v1.0.0
    • 12.77
    • Published

    devrail

    Security & Quality Guardrails - Adoption-first developer discipline. Block new issues, accept existing ones with baseline mode.

    • v0.1.0
    • 12.77
    • Published

    @clyrolabs/vibesecurity

    Servidor MCP (Model Context Protocol) com Zero Trust para análise de segurança com Trivy. Protege workspaces contra Path Traversal, executa scans de vulnerabilidade e gera patches de correção.

    • v1.0.0
    • 12.73
    • Published

    rkiza-agents

    Cursor agent skills and configs. Installs into your project's .agents folder.

    • v0.1.3
    • 12.36
    • Published

    omniaudit-localhost

    OmniAudit Local CLI - Smart contract security scanner with local execution and connector session support

    • v1.0.2
    • 12.23
    • Published

    gh-ghas-fixer

    GitHub Advanced Security autofix CLI tool for code scanning alerts

    • v1.4.0
    • 12.17
    • Published

    react-security-scanner

    A comprehensive React security scanner with 45+ customizable rules covering XSS, injection attacks, data leaks, and more

    • v1.0.0
    • 12.17
    • Published

    skill-seguridad-ia

    La skill de seguridad más completa para desarrollo con IA. Auditoría de 20 vectores, generación de código seguro, setup de entorno y protocolo de emergencias — todo en un comando.

    • v1.0.0
    • 12.17
    • Published

    ghas-secret-fixer

    GitHub Advanced Security autofix CLI tool for code scanning alerts

    • v1.3.0
    • 12.10
    • Published

    ghas-fixer

    GitHub Advanced Security autofix CLI tool for code scanning alerts

    • v1.3.0
    • 12.02
    • Published

    codesentinel-ai

    AI-powered security scanner for your codebase. Scan for vulnerabilities, get risk scores, auto-report on GitLab MRs.

    • v1.0.0
    • 11.69
    • Published

    @devdonzo/the-sentinel

    Autonomous SRE & Security Orchestration Agent - Automatically scan, fix, and patch security vulnerabilities in your repositories

    • v1.0.0
    • 11.26
    • Published

    npm-acadia-guardian

    Multi-layer security scanner for npm packages to detect supply chain attacks

    • v1.0.0
    • 10.97
    • Published

    kafkacode

    AI-powered privacy and compliance scanner by KafkaLabs - identify PII leaks, secrets, and compliance violations

    • v1.2.0
    • 10.76
    • Published

    securedx

    Graduated security gates for DevSecOps pipelines - A developer-centric approach to security enforcement with configurable severity thresholds and productivity analytics

      • v2.0.1
      • 10.72
      • Published

      code-health-copilot

      Automated code health and security analysis for modern web projects. Find and fix issues before they become a problem.

      • v1.0.0
      • 10.66
      • Published

      @iflow-mcp/gnlds-mcp-cve-intelligence-server-lite

      Lite Model Context Protocol server for comprehensive CVE intelligence gathering with multi-source exploit discovery, designed for security professionals and cybersecurity researchers

      • v0.1.1
      • 10.22
      • Published

      ghostcheck

      AI code vulnerability scanner — catches hallucinated packages, phantom APIs, and insecure patterns before you commit. Zero-config, offline, under 2 seconds.

      • v0.1.0
      • 10.22
      • Published

      claude-aspm-scan

      Claude Code skill for Application Security Posture Management — runs Semgrep SAST and optional Shannon pentesting, generates ASPM_SCAN.md reports

      • v1.0.0
      • 10.07
      • Published

      vite-plugin-react-security

      Vite plugin for React Security Scanner - Automatically scan your React code for security vulnerabilities during build

      • v1.0.0
      • 9.03
      • Published

      prompt-cop

      A lightweight security tool to detect potential prompt injection vulnerabilities in code files

      • v2.0.0
      • 9.03
      • Published

      @redpillsec/cli

      RedPill Security CLI - OpenAPI security scanner that reveals vulnerabilities in your API specifications

      • v1.0.1
      • 8.85
      • Published

      webpack-plugin-react-security

      Webpack plugin for React Security Scanner - Automatically scan your React code for security vulnerabilities during build

      • v1.0.0
      • 8.80
      • Published

      react-native-lupin

      Fast, beautiful CLI security scanner for React Native and Expo bundles. Detects API keys, secrets, and 60+ mobile security vulnerabilities.

      • v1.3.0
      • 8.71
      • Published

      gha-secret-fixer

      GitHub Advanced Security autofix CLI tool for code scanning alerts

      • v1.1.0
      • 8.67
      • Published

      cli-depsnap

      A high-performance CLI tool for checking npm dependencies

      • v1.0.0
      • 7.96
      • Published

      @sathyendra/security-checker

      Stop npm supply-chain attacks before they execute. Zero-dependency security scanner: malicious package detection, lockfile audit, dropper detection, integrity checks, OWASP A03/A05/A08/A10 coverage, CycloneDX SBOM & VEX reports, provenance verification, s

      • v1.26.0
      • 4.37
      • Published

      npm-risk

      A zero-dependency CLI that checks npm packages for basic supply-chain risk signals before you install them.

      • v1.0.1
      • 0.00
      • Published

      skill-file-security

      Enterprise-grade AI security skill for any codebase — covers CWE Top 25, OWASP Top 10, ASVS Level 1-3

      • v1.0.0
      • 0.00
      • Published