Utility methods for escaping according to OWASP.
oxlint plugin for React Doctor: diagnose React codebases for security, performance, correctness, accessibility, bundle-size, and architecture issues
Anthropic Sandbox Runtime (ASRT) - A general-purpose tool for wrapping security boundaries around arbitrary processes
Applies best practice security headers to responses. It's a simplified port of HelmetJS
High-performance Static Application Security Testing (SAST) library for detecting security vulnerabilities through taint analysis
Full Court Defense CLI — security scanning for AI agents from your terminal
Detects environment variable issues, usage, and potential security risks.
Static Application Security Testing CLI for detecting security vulnerabilities via taint tracking
security plugin in egg framework
local-first security analysis for TypeScript & JavaScript
Modular AI-assisted network security audit platform — Community Edition
Run OSE Auditor (financial-logic security scanner for Node.js/TypeScript) without installing Python yourself -- this wrapper finds a Python 3 interpreter, installs the ose-auditor PyPI package on first run if needed, and forwards all arguments to it.
MCP security trust-check server for autonomous agents: safe install decisions, risk signals, controls and alternatives before installing MCPs, Skills or tools.
Astro integration to use varlock for .env file loading - adds validation, type-safety, and extra security features
Open-source supply-chain security scanner for npm, PyPI, Cargo, Go, Docker, VS Code extensions, GitHub Actions, IaC and Solana C2. Detects GlassWorm, Shai-Hulud, PPE attacks, dependency confusion and 120+ malware indicators. Generates CycloneDX 1.6 SBOMs
Lightweight runtime security agent for AI-powered apps - detects anomalies, blocks attacks, and provides real-time protection
CLI security scanner for JavaScript and TypeScript projects
observability, deployment, diagnostics, budgets, alerts, and security roles and skills, via rhachet
MCP server for the SCF Controls Platform — security compliance controls, frameworks, evidence, and risk management for AI agents
AI tool security proxy — protect any AI tool server with customizable policies, path/command constraints, rate limiting, and audit logging. Zero code changes required.
A security scanner as fast as a linter, written in Rust. 170+ built-in rules across 10 languages.