Full Court Defense CLI — security scanning for AI agents from your terminal
Static Application Security Testing CLI for detecting security vulnerabilities via taint tracking
Fail-closed Cedar policy gate + signed receipts for AI agent tool calls. Blocks what breaks the rules before it runs, denies on any policy error, and proves the gate is live with a startup self-test.
Shannon - Autonomous white-box AI pentester for web applications and APIs by Keygraph
Salus — CLI de AppSec com IA. Code review, análise de vulnerabilidades, hardening defensivo e auditoria AI/LLM. Modo BYOK (Bring Your Own Key).
Zero-dependency architecture compliance enforcer for Next.js monorepos. Flags violations, suggests fixes, detects patterns, and tracks trend over time.
AI-Powered Legacy Modernization Platform — Install-first, IDE-native, evidence-driven framework that transforms legacy systems into modernization-ready assets.
ailc (AI Life Cycle): автономный оркестратор качества и безопасности кода как MCP-сервер. Обёртка скачивает готовый бинарь для вашей платформы и запускает его.
Enterprise-grade AI security skill for any codebase — covers CWE Top 25, OWASP Top 10, ASVS Level 1-3
Static analysis engine that finds the security gaps a runtime library can't fix — grounded in real vibe-coded Next.js/Supabase mistakes.
SoMi — multi-agent engineering workflow system: plan, code, review — with SOLID/OWASP guardrails, deterministic hooks, and a global ruleset.
MCP server providing Solidity smart contract security analysis tools, OWASP knowledge base, and development utilities for AI agents
The first open-source AI agent built for offensive security. Autonomous pentesting from your terminal.
AI-powered security scanner for git repos — CLI, MCP, API, Web Dashboard, SDK with Cerebras LLM
Secure SDLC agent team — CLI to scaffold docs, hooks, CI, and MCP-ready security workflows
AI Agent Governance for TypeScript — policy enforcement, scoring, compliance, and audit for AI agents
Tiered prompt-injection validation layer. Zero-dep sub-ms Tier 0 core (Node + edge identical), optional local ML + remote guard tiers.
Developer-first security scan orchestrator
Semgrep rules catching the OAuth/OIDC/JWT anti-patterns that AI coding tools systematically produce.
MCP security scanner — 55 tools for runtime inspection, static analysis, config audit, dependency analysis. OWASP MCP Top 10 compliance. OAuth, TLS, fuzz testing, prompt injection, tool mutation detection. 100% local, zero external API calls.
Creates CycloneDX Software Bill of Materials (SBOM) from source or container image