Todas las etiquetas
Etiqueta del catálogo

#owasp

Todos los repositorios del registro público que llevan esta etiqueta, procedente de sus topics de GitHub o de las palabras clave que publican sus registros de paquetes. La salud se mide con la misma metodología versionada que el resto del registro.

26 registros
Con la etiqueta «owasp»Ordenado por índice de salud
npm · Go · crates.io
86Excelenteíndice de salud
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 4869↓ 12.3K/mes20 jul 2026
MIT20 jul 2026 · métricas 1.13.0
npm · RubyGems
81Buenoíndice de salud
owasp/threat-dragon
An open source threat modeling tool from OWASP
JavaScript · Vue★ 152315 jul 2026
Apache-2.015 jul 2026 · métricas 1.13.0
npm · crates.io
80Buenoíndice de salud
AikidoSec/firewall-node
Zen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.
TypeScript · JavaScript★ 201↓ 179.4K/mes22 jul 2026
Licencia propia22 jul 2026 · métricas 1.13.0
PyPI · npm
80Buenoíndice de salud
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5301/mes16 jul 2026
Apache-2.016 jul 2026 · métricas 1.13.0
PyPI
76Buenoíndice de salud
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 11317 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm · Maven · NuGet +1
76Buenoíndice de salud
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1012↓ 719.2K/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm
75Buenoíndice de salud
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1266↓ 2624/mes23 jul 2026
AGPL-3.023 jul 2026 · métricas 1.13.0
npm
74Buenoíndice de salud
OWASP/cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
TypeScript★ 635↓ 20.2K/mes16 jul 2026
MIT16 jul 2026 · métricas 1.13.0
Go
74Buenoíndice de salud
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14617 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
PyPI
74Buenoíndice de salud
owasp/docksec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 46017 jul 2026
MIT17 jul 2026 · métricas 1.13.0
Go
72Buenoíndice de salud
l3montree-dev/flawfix
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 14618 jul 2026
Licencia propia18 jul 2026 · métricas 1.13.0
npm
71Buenoíndice de salud
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2247/mes15 jul 2026
MIT15 jul 2026 · métricas 1.13.0
NuGet
70Buenoíndice de salud
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 2822 jul 2026
Apache-2.022 jul 2026 · métricas 1.13.0
npm · Go
70Buenoíndice de salud
daveshanley/vacuum
vacuum is the worlds fastest and most versatile OpenAPI, AsyncAPI & JSON Schema linter, docs generator and toolkit. It tears through API specs at light speed. 100% compatible with Spectral rulesets, and OpenAPI 3.0, 3.1 and 3.2
Go★ 1103↓ 169.8K/mes19 jul 2026
MIT19 jul 2026 · métricas 1.13.0
npm · PyPI
68Moderadoíndice de salud
Agent-Threat-Rule/agent-threat-rules
Open detection standard -- like Sigma, but for AI agents. 425 rules, shipped in Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H. 97.1% recall on NVIDIA garak. NIST OSCAL Path 1.
TypeScript★ 314↓ 9370/mes16 jul 2026
MIT16 jul 2026 · métricas 1.13.0
Go
66Moderadoíndice de salud
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 821 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
PyPI
65Moderadoíndice de salud
msaleme/red-team-blue-team-agent-fabric
540 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, MCP tool-poisoning reproduction. v4.9.1
Python★ 20↓ 667/mes20 jul 2026
Apache-2.020 jul 2026 · métricas 1.13.0
PyPI
62Moderadoíndice de salud
crucible-security/crucible
pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents
Python★ 45↓ 1793/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
npm
61Moderadoíndice de salud
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6125/mes17 jul 2026
Apache-2.017 jul 2026 · métricas 1.13.0
Go · npm
57Moderadoíndice de salud
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 319 jul 2026
MIT19 jul 2026 · métricas 1.13.0
RubyGems
56Moderadoíndice de salud
dradis/dradis-zap
ZAP plugin for the Dradis Framework
Ruby★ 520 jul 2026
GPL-2.020 jul 2026 · métricas 1.13.0
PyPI · crates.io · Maven +2
56Moderadoíndice de salud
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 1217 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0
RubyGems
54Moderadoíndice de salud
urbanadventurer/WhatWeb
Next generation web scanner
Ruby★ 673522 jul 2026
GPL-2.022 jul 2026 · métricas 1.13.0
npm
52Moderadoíndice de salud
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 46319 jul 2026
AGPL-3.019 jul 2026 · métricas 1.13.0
PyPI
49En riesgoíndice de salud
CycloneDX/cyclonedx-python
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Python★ 386↓ 2.1M/mes21 jul 2026
Apache-2.021 jul 2026 · métricas 1.13.0
PyPI · npm
35En riesgoíndice de salud
Stiimy/briar
🥀 Autonomous AI Pentester — find vulns before hackers do. Free, open source, Ollama-powered.
Python★ 1↓ 78/mes17 jul 2026
Licencia propia17 jul 2026 · métricas 1.13.0