All tags
Catalogue tag

#owasp

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

26 records
Tagged “owasp”Ranked by health index
npm · Go · crates.io
86Excellenthealth index
microsoft/agent-governance-toolkit
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 4,869↓ 12.3K/moJul 20, 2026
MITJul 20, 2026 · metrics 1.13.0
npm · RubyGems
81Goodhealth index
owasp/threat-dragon
An open source threat modeling tool from OWASP
JavaScript · Vue★ 1,523Jul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 1.13.0
npm · crates.io
80Goodhealth index
AikidoSec/firewall-node
Zen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.
TypeScript · JavaScript★ 201↓ 179.4K/moJul 22, 2026
Custom licenseJul 22, 2026 · metrics 1.13.0
PyPI · npm
80Goodhealth index
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
Apache-2.0Jul 16, 2026 · metrics 1.13.0
PyPI
76Goodhealth index
CycloneDX/cyclonedx-python-lib
Functionality and DataModels of OWASP CycloneDX for Python
Python★ 113Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm · Maven · NuGet +1
76Goodhealth index
cdxgen/cdxgen
Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,012↓ 719.2K/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm
75Goodhealth index
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
AGPL-3.0Jul 23, 2026 · metrics 1.13.0
npm
74Goodhealth index
OWASP/cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
TypeScript★ 635↓ 20.2K/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
Go
74Goodhealth index
l3montree-dev/devguard
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
PyPI
74Goodhealth index
owasp/docksec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 460Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go
72Goodhealth index
l3montree-dev/flawfix
DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 18, 2026
Custom licenseJul 18, 2026 · metrics 1.13.0
npm
71Goodhealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
NuGet
70Goodhealth index
CycloneDX/cyclonedx-dotnet-library
.NET library to consume and produce CycloneDX Software Bill of Materials (SBOM)
C#★ 28Jul 22, 2026
Apache-2.0Jul 22, 2026 · metrics 1.13.0
npm · Go
70Goodhealth index
daveshanley/vacuum
vacuum is the worlds fastest and most versatile OpenAPI, AsyncAPI & JSON Schema linter, docs generator and toolkit. It tears through API specs at light speed. 100% compatible with Spectral rulesets, and OpenAPI 3.0, 3.1 and 3.2
Go★ 1,103↓ 169.8K/moJul 19, 2026
MITJul 19, 2026 · metrics 1.13.0
npm · PyPI
68Moderatehealth index
Agent-Threat-Rule/agent-threat-rules
Open detection standard -- like Sigma, but for AI agents. 425 rules, shipped in Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H. 97.1% recall on NVIDIA garak. NIST OSCAL Path 1.
TypeScript★ 314↓ 9,370/moJul 16, 2026
MITJul 16, 2026 · metrics 1.13.0
Go
66Moderatehealth index
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
PyPI
65Moderatehealth index
msaleme/red-team-blue-team-agent-fabric
540 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, MCP tool-poisoning reproduction. v4.9.1
Python★ 20↓ 667/moJul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 1.13.0
PyPI
62Moderatehealth index
crucible-security/crucible
pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents
Python★ 45↓ 1,793/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
npm
61Moderatehealth index
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 1.13.0
Go · npm
57Moderatehealth index
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 3Jul 19, 2026
MITJul 19, 2026 · metrics 1.13.0
RubyGems
56Moderatehealth index
dradis/dradis-zap
ZAP plugin for the Dradis Framework
Ruby★ 5Jul 20, 2026
GPL-2.0Jul 20, 2026 · metrics 1.13.0
PyPI · crates.io · Maven +2
56Moderatehealth index
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
RubyGems
54Moderatehealth index
urbanadventurer/WhatWeb
Next generation web scanner
Ruby★ 6,735Jul 22, 2026
GPL-2.0Jul 22, 2026 · metrics 1.13.0
npm
52Moderatehealth index
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 463Jul 19, 2026
AGPL-3.0Jul 19, 2026 · metrics 1.13.0
PyPI
49At riskhealth index
CycloneDX/cyclonedx-python
CycloneDX Software Bill of Materials (SBOM) generator for Python projects and environments
Python★ 386↓ 2.1M/moJul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
PyPI · npm
35At riskhealth index
Stiimy/briar
🥀 Autonomous AI Pentester — find vulns before hackers do. Free, open source, Ollama-powered.
Python★ 1↓ 78/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0