All tags
Catalogue tag

#owasp

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

48 records
Tagged “owasp”Ranked by health index
Go
75Goodhealth index
RAJANAGORI/Nightingale
Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes preconfigured with all essential tools and utilities required for efficient Vulnerability Assessment and Penetration Testing (VAPT), streamlining the setup process for security professionals.
Dockerfile · Shell · Python★ 313Aug 4, 2026
GPL-3.0Aug 4, 2026 · metrics 2.10.0
PyPI
75Goodhealth index
msaleme/red-team-blue-team-agent-fabric
540 security tests for AI agent systems — MCP, A2A, x402/L402, decision governance, benchmark integrity, skill supply chain. AIUC-1 pre-cert, NIST AI 800-2 aligned, MCP tool-poisoning reproduction. v4.9.1
Python★ 20↓ 667/moJul 20, 2026
Apache-2.0Jul 20, 2026 · metrics 2.10.0
PyPI · npm
71Goodhealth index
vaquarkhan/MCP-Bastion
MCP-Bastion: The Zero-Infrastructure Runtime Middleware ,Enterprise-Grade Security Middleware for the Model Context Protocol (MCP)
Python★ 4↓ 3,959/moAug 16, 2026
Custom licenseAug 16, 2026 · metrics 2.10.0
npm
69Goodhealth index
KryptSec/oasis
Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.
TypeScript★ 29↓ 39/moAug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
PyPI
69Goodhealth index
crucible-security/crucible
pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents
Python★ 45↓ 1,793/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
npm
69Goodhealth index
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
PyPI
67Goodhealth index
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 2Jul 31, 2026
MITJul 31, 2026 · metrics 2.10.0
Go · npm
62Moderatehealth index
scagogogo/cwe-skills
AI-native CWE (Common Weakness Enumeration) integration layer — Skills, Go SDK, CLI & MCP. Ship CVE/CWE tooling to SAST/DAST, vuln-management & AI agents.
Go★ 3Jul 19, 2026
MITJul 19, 2026 · metrics 2.10.0
RubyGems
59Moderatehealth index
dradis/dradis-zap
ZAP plugin for the Dradis Framework
Ruby★ 5Jul 20, 2026
GPL-2.0Jul 20, 2026 · metrics 2.10.0
PyPI · crates.io · Maven +2
57Moderatehealth index
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
RubyGems
54Moderatehealth index
urbanadventurer/WhatWeb
Next generation web scanner
Ruby★ 6,801Aug 28, 2026
GPL-2.0Aug 28, 2026 · metrics 2.10.0
npm
51Moderatehealth index
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 463Jul 19, 2026
AGPL-3.0Jul 19, 2026 · metrics 2.10.0
NuGet
50Moderatehealth index
pumasecurity/puma-scan
Puma Scan is a software security Visual Studio extension that provides real time, continuous source code analysis as development teams write code. Vulnerabilities are immediately displayed in the development environment as spell check and compiler warnings, preventing security bugs from entering your applications.
C#★ 447Aug 7, 2026
MPL-2.0Aug 7, 2026 · metrics 2.10.0
RubyGems
47Weakhealth index
OWASP/www-project-eks-goat
OWASP EKS Goat is a deliberately vulnerable EKS cluster environment to explore AWS cloud-native security through hands-on attack and defense labs with walkthrough.
Shell · Python★ 46Aug 4, 2026
GPL-3.0Aug 4, 2026 · metrics 2.10.0
npm
45Weakhealth index
ArisRoman/cyberaudit-skill
Universal security audit skill for AI agents. 52 pure Markdown files encoding 15 years of pentest expertise — web & mobile security, OWASP-aligned, CVSS scoring, compliance checks, zero dependencies.
TypeScript · JavaScript★ 0↓ 2,331/moJul 25, 2026
No licenseJul 25, 2026 · metrics 2.10.0
Go
34At Riskhealth index
microcosm-cc/bluemonday
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
Go★ 3,704Jul 30, 2026
BSD-3-ClauseJul 30, 2026 · metrics 2.10.0
PyPI · npm
29At Riskhealth index
Stiimy/briar
🥀 Autonomous AI Pentester — find vulns before hackers do. Free, open source, Ollama-powered.
Python★ 1↓ 78/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0