Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Static Application Security Testing CLI for detecting security vulnerabilities via taint tracking
Trident — AI penetration-testing agent. Run it with npx trident-tui ; it bootstraps everything and prompts for your API key.
AI-powered static analysis CLI with LLM-enhanced vulnerability detection
LLM SAST skills — turn your AI coding assistant into a SAST scanner for your codebase.
local-first security analysis for TypeScript & JavaScript
Modular AI-assisted network security audit platform — Community Edition
Scanning engine for lockhawk: lockfile parsing, OSV.dev vulnerability matching, CVSS v3/v4 scoring, and SARIF/JUnit/HTML reports
Fast, free, accurate npm dependency vulnerability scanner for local + CI/CD with an interactive HTML dashboard and SARIF/JUnit output, powered by OSV.dev
Scan your codebase for quantum-vulnerable cryptography
A security scanner as fast as a linter, written in Rust. 170+ built-in rules across 10 languages.
An ultra-modular, type-safe Node.js CLI tool used to scaffold new project templates (CLI, Webpage, Webapp, Fullstack) with best-practice configurations pre-installed.
Supply-chain security audit for npm packages, as an MCP tool and a pay-per-call x402 endpoint. Cross-references known CVE/GHSA advisories (OSV.dev) and detects typosquatting, malicious install scripts, token/credential exfiltration and other red flags BEF
Trustify :: Dependency Analytics :: API
SIC free code scanner — read-only static analysis for hardcoded secrets, dangerous patterns, and dependency CVEs. Zero runtime dependencies.
ShipSafe MCP server — let your AI coding agent scan the code it writes for security vulnerabilities, in-loop
DataNexus MCP — AI-Ready public data intelligence. 55 tools: CVE risk verdicts, SBOM licence policy, frontend security (manifest audit, CI scanner, typosquatting), licence compatibility, nonprofit 990 trends, SBOM monitoring, federal contracts, NPI lookup
Security scanner for AI-generated code — find vulnerabilities before you ship
Pup — an AI-native, evidence-based application security platform: contextual AI SAST, reachability-based SCA, and threat modelling for JavaScript/TypeScript.
An open source software supply chain security tool built for developers and security engineers
Official Trace CLI for vulnerability intelligence in your terminal
MCP server providing Solidity smart contract security analysis tools, OWASP knowledge base, and development utilities for AI agents
Make your AI coding agent dependency-security aware. Checks your project's dependencies against known CVEs so your agent can fix what it introduced — before merge.