Template-based vulnerability scanner.
Tools for devsecops
Shift-left scanning in CI/CD pipelines.
66 tools indexed
Adversary emulation for AI agents, LLM apps and MCP servers
Continuous fuzzing for open source.
Dependency vulnerability scanner.
Open-source threat modeling.
Open-source web app scanner.
Policy-as-code across the stack.
File-based agent workspace for source-guided whitebox security review
Open-source AI agent firewall for MCP and agent egress.
Multi-cloud security posture.
QARK
—Quick Android Review Kit.
Detect vulnerable JS libraries.
Self-hosted open-source WAF.
API fuzzer from OpenAPI/GraphQL.
Lightweight static analysis.
Solidity / Vyper static analyzer.
Open-source SCA + IaC scanner.
Solidity inspector.
Syft
—Generate SBOMs from containers and source code.
Cloud-native secrets manager.
eBPF-based runtime security.
Cross-platform data-protection framework.
Open-source cloud-native protection platform.
Container and IaC vulnerability scanner.