npm · Go · crates.io96Exceptionalhealth index

microsoft/agent-governance-toolkitAI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Python★ 6,138↓ 14.7K/moAug 28, 2026
PyPI95Exceptionalhealth index
Python★ 390↓ 2.2M/moAug 27, 2026
npm · RubyGems95Exceptionalhealth index
JavaScript · Vue★ 1,523Jul 15, 2026
npm · crates.io94Exceptionalhealth index
AikidoSec/firewall-nodeZen protects your Node app against attacks with one line of code. Get peace of mind— at runtime.
TypeScript · JavaScript★ 201↓ 179.4K/moJul 22, 2026
PyPI · npm94Exceptionalhealth index
msaad00/agent-bomOpen security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
PyPI · npm94Exceptionalhealth index
sattyamjjain/agent-audit-kitStatic scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/moAug 2, 2026
npm · Maven · NuGet +192Excellenthealth index
cdxgen/cdxgenCreates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with automatic submission to Dependency Track server
JavaScript★ 1,018↓ 745.3K/moJul 28, 2026
npm91Excellenthealth index
CyberStrikeus/CyberStrikeOpen-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
Packagist91Excellenthealth index
PHP★ 87↓ 91.9K/moJul 29, 2026
PyPI90Excellenthealth index
Python★ 113Jul 17, 2026
PyPI · RubyGems90Excellenthealth index
Python★ 155↓ 2,902/moAug 25, 2026
owasp-noir/noirHunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
Crystal★ 1,363Aug 4, 2026
PyPI89Excellenthealth index
owasp/docksecAI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.
Python★ 460Jul 17, 2026
npm88Excellenthealth index
OWASP/cve-lite-cliFast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
TypeScript★ 635↓ 20.2K/moJul 16, 2026
npm88Excellenthealth index

asamassekou10/ship-safeCLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
PyPI88Excellenthealth index
Python★ 7Jul 31, 2026
Go88Excellenthealth index
l3montree-dev/devguardDevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 17, 2026
Go87Excellenthealth index
l3montree-dev/flawfixDevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your Vulnerability Scanners, Security Framework Documentation made easy - OWASP Incubating Project
Go★ 146Jul 18, 2026
npm86Excellenthealth index
ofri-peretz/eslintSecurity & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/moJul 25, 2026
npm84Excellenthealth index

KeygraphHQ/shannonShannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/moAug 5, 2026
npm · Go84Excellenthealth index
daveshanley/vacuumvacuum is the worlds fastest and most versatile OpenAPI, AsyncAPI & JSON Schema linter, docs generator and toolkit. It tears through API specs at light speed. 100% compatible with Spectral rulesets, and OpenAPI 3.0, 3.1 and 3.2
Go★ 1,103↓ 169.8K/moJul 19, 2026
npm · PyPI84Excellenthealth index
openshield-org/openshieldOpen source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with one command
Python · JavaScript★ 55Aug 4, 2026
C#★ 533Aug 21, 2026
NuGet83Excellenthealth index
C#★ 28Jul 22, 2026
Maven83Excellenthealth index
Java★ 375Jul 30, 2026
npm · PyPI81Excellenthealth index
Agent-Threat-Rule/agent-threat-rulesOpen detection standard -- like Sigma, but for AI agents. 425 rules, shipped in Microsoft AGT, Cisco AI Defense, MISP, OWASP A-S-R-H. 97.1% recall on NVIDIA garak. NIST OSCAL Path 1.
TypeScript★ 314↓ 9,370/moJul 16, 2026
Go81Excellenthealth index
Go★ 163Sep 3, 2026
Go81Excellenthealth index
airomhq/airomOpen-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 23, 2026
npm80Excellenthealth index
lua-ai-global/governanceZero-dependency TypeScript SDK for AI agent governance: policy enforcement, injection detection, tamper-evident audit, and standards mapping (EU AI Act, OWASP, NIST, ISO 42001)
TypeScript★ 25↓ 3,545/moJul 26, 2026
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026