Trivy is a comprehensive security scanner used to detect vulnerabilities, misconfigurations, secrets, and SBOMs across various targets including containers, Kubernetes, and code repositories.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONA curated collection of Web Application Security payloads and bypasses for pentesting and CTFs, covering vulnerability descriptions, exploitation techniques, and Burp Intruder file sets.
Template-driven vulnerability scanner with a YAML DSL, community templates, and support for HTTP, DNS, TCP, SSL, WHOIS, JavaScript, headless browser, fuzzing, CI/CD integration, and multiple report formats.
Infisical is an open-source platform for secrets management, certificate/PKI lifecycle, key management, and privileged access management. Features include a dashboard, CLI, SDKs and API, secret syncs and rotation, leak scanning, a Kubernetes operator, and self-hosting via Docker.
An experimental security extension for the Model Context Protocol (MCP) providing runtime evidence for tool calls via HTTP message signatures and mTLS.
Nirmata Runtime is a Kubernetes-native runtime enforcement tool using eBPF and Kyverno-style CEL policies to monitor and block file opens, execs, network traffic, protocols, and DNS queries for AI workloads.
pg_vault_tde is a PostgreSQL extension for Transparent Data Encryption (TDE) using AES-256-GCM. It supports key management with HashiCorp Vault, OpenBao, or local PKCS#12 wallets, and PKCS#11 HSMs. It encrypts data at the Table Access Method layer without modifying PostgreSQL core.
AgentLeak is an open-source privacy testing tool for AI agents. It detects data leaks across tool calls, memory, and logs using a local Python SDK, CLI, and MCP tools, providing redacted reports and CI gates without cloud dependencies.
Web of Flaws is a structured, markdown-first catalog of web security vulnerabilities and secure code replacements designed for developers, security engineers, and AI coding agents.
SOPS is a flexible editor for encrypted files that supports multiple data formats and integrates with various cloud KMS providers and encryption tools.
VGS Show Android SDK lets apps securely display sensitive data from a vault using customizable views and reveal flows, without routing raw data through client systems.
Lego is a versatile ACME client and Go library for obtaining, renewing, and managing SSL/TLS certificates from Let's Encrypt and other CAs. It supports CLI usage and programmatic integration, featuring over 200 DNS provider plugins for automated DNS-01 challenges, plus HTTP-01 and TLS-ALPN-01 support.
A curated list of Android security resources including tools for static/dynamic analysis, reverse engineering, fuzzing, and vulnerability scanning.
Terraform provider for managing SAP Cloud Identity Services resources via infrastructure-as-code, with OpenTofu compatibility.
A curated list of open source tools for AWS security covering defensive hardening, offensive testing, auditing, DFIR, and more.
MCP Arcade is a command-line testing tool that runs a small catalog of experiments, called atoms, against MCP servers, judging results by the JSON-RPC wire and sandbox file changes rather than by tool descriptions or model prose.
Strix is an open-source AI-powered penetration testing tool that uses autonomous agents to identify, validate, and fix application vulnerabilities through real proof-of-concept exploits.
A Go library for parsing, verifying, generating, and signing JSON Web Tokens (JWT), supporting HMAC SHA, RSA, RSA-PSS, and ECDSA algorithms with RFC 7519 compliance.
secretgenerator is an auditable CSPRNG‑backed credential generator for AI agents and machine‑readable pipelines. It provides stable JSON schema, NIST entropy floors, SLSA 3 and cosign signed releases, with CLI and libraries in Go, Python, Rust, and an MCP server.
PyFlow is a research-oriented static analysis framework for Python, offering IRs, program analysis, optimization passes, security checking, supply-chain analysis, and CLI/LSP/MCP tooling.