Highlights
- Pro
Lists (1)
Sort Name ascending (A-Z)
Stars
A compilation of resources in the software supply chain security domain, with emphasis on open source
Discover hidden dependencies across repositories, container images, cloud runtimes, and endpoints, unifying SBOM, vulnerability, malware, and deployment evidence in one platform.
Transaction Tokens (RFC 8693) for Kubernetes — seal identity, context, and authorization across multi-hop agent workflows via AgentGateway + ext_authz.
Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database.
This is where I will publish community facing documents that I want to easily share with the community
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
A feature-rich command-line audio/video downloader
A tool for creating and running Linux containers using lightweight virtual machines on a Mac. It is written in Swift, and optimized for Apple silicon.
This repo has all the resources you need to become an amazing security engineer!
A modern runtime for JavaScript and TypeScript.
A GitHub action for @security-alert/sarif-to-comment
A collection of DESIGN.md files analysis by popular brand design systems. Drop one into your project and let coding agents generate a matching UI.
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before t…
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
OpenShell is the safe, private runtime for autonomous AI agents.
Device Bound Session Credentials: A Protocol for Protecting From Cookie Theft
Security Scanner for Agent Skills
Generate xBOMs enriched with AI, SaaS, Crypto and more using Static Code Analysis
Security layer for AI coding agents. Works with Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Pi Agent and more.
PMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
A toolkit with common assertions and mocks that plays nicely with the standard library