PyPI · npm99Exceptionalhealth index

prowler-cloud/prowlerProwler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.
Python · TypeScript★ 14.7K↓ 217.7K/moAug 27, 2026
Go99Exceptionalhealth index
Go★ 27.4KAug 13, 2026
Go98Exceptionalhealth index
chainloop-dev/chainloopSDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more
Go★ 570Jul 16, 2026
PyPI96Exceptionalhealth index
Python · TypeScript★ 42↓ 4,913/moSep 5, 2026
PyPI95Exceptionalhealth index

GitGuardian/ggshieldDetect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Python★ 1,985Aug 13, 2026
PyPI95Exceptionalhealth index

xonsh/xonsh🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly.
Python★ 9,599Aug 12, 2026
npm · PyPI94Exceptionalhealth index
Python · HTML · JavaScript★ 10.9KAug 28, 2026
PyPI · npm94Exceptionalhealth index
msaad00/agent-bomOpen security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
PyPI93Exceptionalhealth index
cisco-open/forgeForgeMT is a multi-tenant platform for self-hosted GitHub Actions runners on AWS. It gives platform teams an IaC-driven way to operate ephemeral EC2 runners and ARC/Kubernetes runner scale sets for many tenant repositories.
HCL · Python★ 210Jul 21, 2026
PyPI · crates.io · npm93Exceptionalhealth index

hashgraph-online/hol-guardOpen-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Python · TypeScript★ 557↓ 95.5K/moSep 5, 2026
Go93Exceptionalhealth index
mindburn-labs/helm-ai-kernelFail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 53Jul 17, 2026
PyPI · crates.io93Exceptionalhealth index
mongodb/kingfisherDetect leaked secrets + live validation. Map blast radius across your stack. Revoke fast. 1,000+ rules.
Rust★ 1,174Jul 19, 2026
Go · npm92Excellenthealth index
safedep/pmgPMG protects developers, AI agents from malicious open source packages using proxy, sandbox and SafeDep's threat intelligence feed.
Go★ 464Jul 17, 2026
npm91Excellenthealth index
CyberStrikeus/CyberStrikeOpen-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
Shell · Makefile★ 1,389Aug 1, 2026
Go · Maven91Excellenthealth index
praetorian-inc/titusHigh-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 638Jul 19, 2026
Go90Excellenthealth index

cynative/cynativeOpen-source framework for security agents with live, read-only access to your infrastructure. Audit AWS, GCP, Azure, Kubernetes, GitHub and GitLab as one system for privilege escalation, public exposure, leaked credentials and more, with agents you write in one markdown file.
Go · Shell★ 197Sep 5, 2026
Go90Excellenthealth index
mindburn-labs/helm-ossFail-closed execution firewall for AI agents: quarantine MCP tools, proxy OpenAI-compatible requests, emit signed receipts, and verify EvidencePacks offline.
Go · Java★ 53Jul 18, 2026
PyPI90Excellenthealth index

pyupio/safetySafety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.
Python★ 1,995↓ 4.5M/moAug 27, 2026
owasp-noir/noirHunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
Crystal★ 1,363Aug 4, 2026
PyPI89Excellenthealth index
owasp/docksecAI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 460Jul 17, 2026
npm88Excellenthealth index

asamassekou10/ship-safeCLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
Go88Excellenthealth index
Go★ 1,729Aug 20, 2026
PyPI88Excellenthealth index
Python★ 7Jul 31, 2026
Go88Excellenthealth index
l3montree-dev/devguardDevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 17, 2026
Go87Excellenthealth index
l3montree-dev/flawfixDevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 18, 2026
Go86Excellenthealth index
Nox-HQ/noxOpen-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 0Jul 24, 2026
Go · PyPI86Excellenthealth index
bomly-dev/bomly-cliFree, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 9Jul 17, 2026
npm86Excellenthealth index
ofri-peretz/eslintSecurity & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/moJul 25, 2026
PyPI86Excellenthealth index
stephrobert/dsoxlabDevSecOps XL Labs — a domain-agnostic CLI framework to drive hands-on learning labs across multiple repositories
Python★ 55↓ 3,355/moJul 27, 2026