> cat /dev/github | grep security-tools

~/hackyfeed $

A cybersecurity tools aggregator — discover the latest pentesting, red team, and offensive security tools from GitHub.

sort: ( this page )

trawld

trawld is a package vulnerability monitoring tool designed for developer fleets, enabling continuous oversight of project dependencies across enrolled machines. It features a real-time dashboard for vulnerability tracking using a Cloud Brain and a global npm agent that automates project discovery, scheduled rescans, and maintains live status updates. With seamless onboarding and no code modifications required, trawld enhances security management for development environments.

terraview

Terraview is an open-source security analysis tool designed for Terraform plans that integrates static scanners like Checkov, Trivy, and Terrascan with AI contextual analysis, executing these processes in parallel. It inspects infrastructure provisioned with Terraform to identify security misconfigurations and compliance issues while enriching results through multi-provider contextual insights. Notable features include built-in security scanner capabilities, seamless configuration management, and native policy-as-code support, all without external dependencies.

synapse-ce

Synapse is a governed control plane designed for comprehensive software composition analysis, vulnerability detection, and reporting, facilitating security assessments in a controlled environment. Its primary use case revolves around automating security workflows, ensuring tamper-evident evidence collection, and allowing for deterministic scanning across various ecosystems with multiple built-in scanners. Notable features include a robust SBOM generation, risk-based prioritization of findings, and strict adherence to authorization and scope constraints before tool execution.

symfony-security-auditor

Symfony Security Auditor is an AI-driven security auditing tool designed for Symfony applications, focusing on identifying application-level flaws that traditional static analysis tools may overlook. It features an adversarial Attacker and Reviewer loop to validate vulnerabilities and produces reports in multiple formats, including JSON and HTML. The auditor can operate in two modes: as a standalone CLI tool or integrated into Symfony applications, providing flexibility for different auditing needs.

still_active

`still_active` is a dependency auditing tool that evaluates the maintenance status of packages across multiple ecosystems, including Ruby, npm, PyPI, Cargo, and more, by identifying archived repositories, lack of recent releases, and vulnerabilities that remain unpatched. Its notable features include last-commit activity checks, OpenSSF scorecard evaluations, and detection of “poison-pill” dependencies that may hinder security updates. This tool serves as a complementary addition to existing package management solutions by proactively highlighting risks associated with outdated or abandoned dependencies.

SILENTCHAIN

SILENTCHAIN AI™ - Community Edition is a Burp Suite extension designed for AI-powered passive vulnerability analysis, providing intelligent detection of OWASP Top 10 vulnerabilities and security misconfigurations in real-time HTTP traffic. Notable features include context-aware detection using various AI models, detailed reporting with CWE and OWASP mapping, and robust data privacy measures through automatic sensitive data redaction. The tool enhances traditional security scanning by focusing on real vulnerabilities with zero false positives, making it a significant addition to web application security testing.

Sighthound

Sighthound is a Tree-sitter based static vulnerability scanner designed for identifying security vulnerabilities in source code through AST-aware rules and taint-flow analysis. It supports multiple programming languages, executes scans in parallel, and offers output in various formats including JSON, CSV, and SARIF for integration with GitHub Code Scanning. Notably, Sighthound allows for custom rule packs and provides both pattern and taint mode analysis, catering to complex multi-file projects.

ShieldEye_ComplianceScan

ShieldEye ComplianceScan is a web compliance and vulnerability scanner that assesses web targets against key security standards including GDPR, PCI-DSS, and ISO 27001. It features a GTK4 desktop interface, a CLI for automated scanning, and a REST API for integration, while providing detailed reports that include CVSS v3.1 scoring and export options in various formats. The tool evaluates critical aspects like TLS configuration, security headers, and cookie settings, making it suitable for regular compliance checks and configuration sanity evaluations.

Shield-Eye-Core

ShieldEye Core is a desktop network security scanner designed for Linux, primarily aimed at security researchers, pentesters, and system administrators. It utilizes Nmap for comprehensive port and service discovery, identifies vulnerabilities in common CMS platforms by cross-referencing with the CIRCL CVE database, and evaluates HTTP security headers, all presented through a GTK 4 GUI with intuitive reporting features. Key functionalities include customizable scanning profiles, a detailed analysis of web security, and robust safety measures against unauthorized access and disruption.

Shai-Hulud-2.0-Detector

The Shai-Hulud 2.0 Detector is a cybersecurity tool designed to protect projects from the Shai-Hulud 2.0 npm supply chain attack, a significant threat that compromised numerous packages in the npm ecosystem. Its primary use case involves detecting vulnerable packages and facilitating community reporting of compromised software, enhancing the security posture of development environments. Notable features include automated daily updates of an affected packages database, advanced configuration options for tailored scanning, and support for various integration methods including GitHub Actions and local CLI usage.

sec-af

SEC-AF is an AI-native security auditing tool that confirms exploitability of vulnerabilities in codebases by providing a detailed data flow trace and verifiable evidence for each finding. It allows users to initiate audits via a single API call or command line interface, returning comprehensive reports that include severity, exact location, and a verdict on each vulnerability. Notably, SEC-AF offers a cost-effective solution for thorough security assessments, typically costing about $1.40 per full audit.

scanner

Bawbel Scanner is an open-source tool designed to assess MCP servers and skill files for vulnerabilities, specifically providing OWASP AIVSS scores without executing any code. Its primary use case includes detecting AVE vulnerabilities and ensuring compliance with the MCP specification, while notable features encompass a variety of focused scans, conformance grading, and vulnerability management functionalities. The tool supports formats for reporting, a public vulnerability database, and provides guidance for remediation, making it a comprehensive solution for security assessments of MCP environments.

RouteVulScan-2.0

RouteVulScan is a passive recursive path probing extension for Burp Suite that leverages the Montoya API to perform low-noise vulnerability detection during web security testing. It automatically scans traffic for hidden endpoints and sensitive files using customizable YAML-based detection rules, allowing users to quickly identify high-value vulnerabilities without the need for manual dictionary management. Key features include automatic path recursion, support for active scanning of individual requests, and a comprehensive rules engine for effective vulnerability assessment.

repomind

RepoMind is an AI-powered tool designed to facilitate the understanding of public GitHub repositories and developer profiles through advanced code reasoning and architecture visualization. It offers zero-setup access for public repositories, context-aware analysis to provide relevant files, security scanning with verification reporting, and real-time feedback during the analysis process. Notable features include automated architecture mapping, a streamlined user interface for discovering trending repositories, and a robust cleaning mechanism through its Agentic Context-Augmented Generation architecture for reliable query responses.

refuse

Refuse is a self-hostable HTTP service that supports the refuse-cli tool, designed to block the installation of vulnerable packages by querying a local SQLite database populated with public vulnerability feeds. It features a REST API for package checks, a built-in admin UI, and frequent updates from various sources, allowing users to verify package safety and enforce security policies during package management operations.

quodeq

Quodeq is an open-source AI-powered tool designed for scanning codebases to detect security vulnerabilities and design flaws, aligning with the ISO 25010 quality dimensions. It provides detailed findings such as grades, violations with line numbers, and fix plans, with every issue mapped to a corresponding CWE identifier. Notably, it operates locally without telemetry, runs on various platforms, and offers both cloud and local model configurations for flexibility and privacy.

presidio-hardened-vuln-scanner

The presidio-hardened-vuln-scanner is a web application vulnerability scanner designed to analyze both a deliberately vulnerable Flask application and its hardened version. It facilitates a comprehensive security assessment through static analysis, dynamic scanning, and manual exploitation, highlighting various vulnerabilities such as SQL injection and XSS, with a structured approach to measure and verify fixes. Notable features include integration with tools like Bandit and pip-audit for static analysis, as well as a custom scanner to dynamically check for vulnerabilities.

plankton

Plankton is a command-line web vulnerability scanner designed to conduct checks against the OWASP Top 10 (2021) vulnerabilities on specified URLs. It generates colorful terminal outputs and supports multiple report formats, including a styled HTML report, JSON, and plain text, enabling users to customize scan parameters with ease. Key features include 12 specific vulnerability checks, configurable options such as timeout and user-agent, and an accessible single-file script for quick deployment.

pi-codex-security

pi-codex-security is a tool that integrates OpenAI Codex Security functionality into pi agent sessions, enabling users to scan repositories for vulnerabilities, review findings by severity, and automatically fix issues. Notable features include customizable scanning options, detailed artifact generation in various formats (e.g., SARIF and JSON), and a user-friendly command interface for initiating scans and managing authentication. This tool is particularly useful for developers who want to enhance their code security seamlessly within their development environment.

perimeter-hardening-suite

BitDefender Total Security Ultimate Protection is a comprehensive cybersecurity suite that functions as a modular framework for fortifying network defenses against a wide array of cyber threats. Its primary use case revolves around system hardening, employing features such as vulnerability scanning, real-time threat correlation, and sandbox-based execution to protect various environments from evolving threats. Notable capabilities include automated policy enforcement, advanced heuristic analysis, and deep kernel inspection for rootkit remediation, all integrated within a responsive interface supporting multilingual operations and continuous 24/7 support.

pentest_skill

Pentest Skill is a comprehensive black-box web penetration testing toolkit designed to streamline the bug bounty workflow through a structured five-phase approach: Intake, Recon, Enum, Hunt, and Report. Notable features include a workflow controller with checkpoints for phase progression, a collection of 48 Python scripts for various testing phases, and an extensive library of attack playbooks and payloads, facilitating targeted vulnerability assessment and reporting.

PenHunter

PenHunter is a modular web vulnerability scanner designed for penetration testers, bug bounty hunters, and security researchers, focused on identifying a wide range of web vulnerabilities, including XSS, SQL Injection, and RCE. It features advanced detection methods, such as boolean and time-based techniques, as well as built-in WAF evasion capabilities, and can integrate with external tools like sqlmap and dalfox. The tool supports concurrent scanning, interactive CLI usage, and provides organized output in multiple formats, enhancing workflow efficiency in security assessments.

opena2a

OpenA2A CLI is a unified command-line interface designed for the OpenA2A security toolchain, enabling users to identify and rectify security vulnerabilities such as credential leaks, shadow AI, and unsigned configurations with a single command. Notable features include automated security reviews and remediation capabilities, Apache 2.0 licensing, and integration with various security-focused sister packages.

OmniStrike

OmniStrike is a state-aware security scanning tool for Burp Suite that enables precise and customizable security testing by allowing users to target individual parameters within requests. It features 14 active scanning engines, 10 technology-aware scanners, and session automation capabilities, alongside optional AI analysis for focused vulnerability testing. This tool is designed to facilitate detailed assessments of modern web technologies while maintaining user control over scanning processes and findings management.

nyx

Nyx is a local-first security scanner designed for cross-language taint analysis of code repositories, providing a sandboxed dynamic verification environment. Its notable features include a user-friendly React-based UI for real-time results, a detailed flow visualizer for tracking data paths, and the ability to persist triage states alongside code commits, ensuring collaboration within teams. Additionally, Nyx can be seamlessly integrated into CI pipelines, generating SARIF reports for GitHub Code Scanning.