actual vulnerability
Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
AI-powered static analysis CLI with LLM-enhanced vulnerability detection
Scanning engine for lockhawk: lockfile parsing, OSV.dev vulnerability matching, CVSS v3/v4 scoring, and SARIF/JUnit/HTML reports
Fast, free, accurate npm dependency vulnerability scanner for local + CI/CD with an interactive HTML dashboard and SARIF/JUnit output, powered by OSV.dev
Official Trace CLI for vulnerability intelligence in your terminal
Patchstack connector for JavaScript applications. Scans your lockfile and reports installed packages to Patchstack for vulnerability monitoring.
Supply-chain security firewall for Node.js — resolves dependencies, scans via OSV.dev and NVD, and enforces configurable vulnerability policies before anything reaches node_modules.
AI-powered vulnerability scanner for your code. Detects security flaws and suggests fixes using ASI:One.
Security Operations Engineer agent for Valora (threat detection, vulnerability management, incident response). Requires valora-plugin-platform.
Software supply chain security MCP server — vulnerability scanning, package analysis, provenance verification, typosquatting detection, dependency intelligence across npm, PyPI, crates.io, Go, and more
Multi-engine container & system vulnerability scanning for AI agents. Wraps Trivy and Grype with cross-engine validation, SBOM generation, and IaC misconfiguration scanning.
Static Application Security Testing CLI for detecting security vulnerabilities via taint tracking
Trident — AI penetration-testing agent. Run it with npx trident-tui ; it bootstraps everything and prompts for your API key.
LLM SAST skills — turn your AI coding assistant into a SAST scanner for your codebase.
local-first security analysis for TypeScript & JavaScript
Modular AI-assisted network security audit platform — Community Edition
Scan your codebase for quantum-vulnerable cryptography
A security scanner as fast as a linter, written in Rust. 170+ built-in rules across 10 languages.
An ultra-modular, type-safe Node.js CLI tool used to scaffold new project templates (CLI, Webpage, Webapp, Fullstack) with best-practice configurations pre-installed.
Supply-chain security audit for npm packages, as an MCP tool and a pay-per-call x402 endpoint. Cross-references known CVE/GHSA advisories (OSV.dev) and detects typosquatting, malicious install scripts, token/credential exfiltration and other red flags BEF
Trustify :: Dependency Analytics :: API
SIC free code scanner — read-only static analysis for hardcoded secrets, dangerous patterns, and dependency CVEs. Zero runtime dependencies.