Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs
Skill-driven Claude PR review. Ship a brand-voice skill, get brand reviews. Each finding cites the skill that motivated it. CLI installs the workflow + a baseline kit; add more from skills.sh.
Trusted install, lockfile, and governance layer for MCP servers
CLI agent for syncing test data to Test Chronicle
Open-source CLI for PR regression-risk, blast-radius, and code-decay analysis
Publish assignment content from GitHub to Vocareum
GitHub Action for validating and rendering XCON code blocks in Markdown.
Open-source CLI for PR regression-risk, blast-radius, and code-decay analysis
Open-source, multi-provider AI code reviewer. Bring your own key (Gemini, OpenAI, Anthropic, Ollama, OpenRouter, Groq, Azure, DeepSeek, Mistral, xAI) — or use the optional ECODrix-hosted relay.
Diff dependency lockfiles across ecosystems — as a GitHub Action, CLI, or library
Open-source HIPAA compliance scanner for healthcare code — CLI for verification-layer.
A deterministic, no-LLM-in-the-loop CI gate that catches agent-PR defects: assertion-free tests, hallucinated symbols, and PR claims that contradict the diff.
Lock your AI app's behavior. Golden datasets + LLM-as-judge + structural assertions in CI.
AI-powered Dependabot security fix agent. Analyzes code with LLM, applies fixes via GitHub API, creates PRs. Works as CLI and GitHub Action.
Diff MCP server public interfaces - CLI tool and GitHub Action
Scan your TypeScript repo for what the move to the native Go compiler (tsgo / TypeScript 7.0) breaks — removed tsconfig flags, Compiler-API-dependent tooling that needs TS 6 side-by-side, and decorator/JSDoc behavior changes. Deterministic CLI + GitHub Ac
Guardrail checks for AI-agent-generated pull requests
Open-source localization quality gate for React and TypeScript projects. Detects missing keys, broken interpolation, and invalid locale files before merge.
Author-side pre-publish conformance & safety linter for MCP (Model Context Protocol) servers — eslint for your MCP server. Checks tool annotations, schema hygiene, tool-poisoning/injection patterns, and registry/distribution metadata before you publish. C
The persistent-memory and runtime-discipline layer for Claude Code. It remembers the corrections you already gave, grounds every edit in real facts before it lands, and — through the Mulahazah engine — turns each fix into a reusable instinct, so a lesson
GitHub Action that blocks AI-hallucinated, nonexistent, and too-new dependencies in pull requests.
GitHub Action for Neurcode - Code adherence verification gatekeeper
Open-source HIPAA compliance scanner for healthcare code. 131 rules, 5 HIPAA categories. CLI + CI/CD + VS Code.
GitHub Action and CLI to convert Markdown (GFM) to Confluence Cloud storage format