PyPI · npm94Exceptionalhealth index
msaad00/agent-bomOpen security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/moJul 16, 2026
PyPI · npm94Exceptionalhealth index
sattyamjjain/agent-audit-kitStatic scanner for MCP-connected AI agent pipelines — 271 rules across 12 categories, 12 compliance frameworks, OWASP Agentic 10/10 + MCP 10/10, GitHub Action, SARIF, public CVE-to-rule ledger.
Python★ 13↓ 2,808/moAug 2, 2026
npm91Excellenthealth index
Siteimprove/alfa:wheelchair: Suite of open and standards-based tools for performing reliable accessibility conformance testing at scale
HTML · TypeScript★ 130↓ 96.3K/moJul 31, 2026
PyPI87Excellenthealth index
Cranot/roam-codeLocal codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5,430/moJul 15, 2026
Go86Excellenthealth index
Nox-HQ/noxOpen-source security scanner with first-class AI app security (prompt injection, embedding leakage, agent over-privilege, MCP hardening). Polyglot AIBOM, SARIF, SBOM. Cosign-signed plugin marketplace. Offline-first, agent-native via MCP.
Go★ 0Jul 24, 2026
Go · PyPI86Excellenthealth index
bomly-dev/bomly-cliFree, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 9Jul 17, 2026
npm86Excellenthealth index
TypeScript★ 38↓ 76.1K/moJul 21, 2026
npm86Excellenthealth index
ofri-peretz/eslintSecurity & code-quality ESLint plugins — 350+ CWE-mapped rules across 18 domains, ESLint + Oxlint. The lint layer AI-generated code needs.
TypeScript · MDX★ 12↓ 77.5K/moJul 25, 2026
npm · PyPI84Excellenthealth index

DNSZLSK/muad-dibReal-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 7,189/moAug 22, 2026
PyPI84Excellenthealth index

squid-protocol/gitgalaxyDeep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 50Aug 22, 2026
Go81Excellenthealth index
airomhq/airomOpen-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 8Jul 23, 2026
npm · crates.io78Goodhealth index
0sec-labs/foxguardA fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/moJul 17, 2026
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026
cpeoples/ansible-security-scanner🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/moJul 17, 2026
Python★ 6↓ 940.1K/moJul 21, 2026
draugr-dev/draugrDeveloper-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 0Jul 19, 2026
npm · PyPI77Goodhealth index
raccioly/docguardThe enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5,005/moJul 21, 2026
npm · Go73Goodhealth index
HodeTech/LeakwatchHigh-performance open-source secret scanner — detect, verify & report leaked API keys, tokens & credentials in code, Git history, container images, and the cloud.
Go★ 2↓ 46/moJul 27, 2026
npm · PyPI73Goodhealth index
oaslananka/boardreadyopsEnd-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3,738/moJul 17, 2026
stainless-code/codemapCut AI-agent token waste ~90% — query a local SQLite structural index of your JS/TS/CSS codebase with SQL in one round-trip instead of 3–5 file reads. Symbols, imports, calls, components, CSS tokens, coverage, markers. CLI, MCP (21 tools), HTTP, GitHub Action, ESM API. 71 recipes; AST+resolver; SARIF/audit/baselines for CI.
TypeScript★ 8↓ 8,315/moJul 26, 2026

Vulnetix/cliAutomate vulnerability triage which prioritizes remediation over discovery
Go · Open Policy Agent★ 25Sep 5, 2026

YawLabs/ctxlintLint your AI agent context files (CLAUDE.md, AGENTS.md, etc.) against your actual codebase
TypeScript★ 7↓ 21.4K/moAug 6, 2026
goklab/guardvibeSecurity infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/moJul 17, 2026
raccioly/websec-validatorLocal-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 2Jul 31, 2026

tiagosilva07/zyrax-guardAudit your AI agent configs before you run them — prompt injection, rogue MCP servers, credential-exfil. Plus dependency vetting.
Go★ 2Aug 28, 2026
Packagist · npm65Goodhealth index
blundergoat/gruff-phpOpinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8,483/moJul 16, 2026
Go · npm62Moderatehealth index

LarsArtmann/art-duplProfessional code clone detection for Go. AST-based structural + semantic detection with suffix tree algorithms, 3 matching modes, 7 output formats, templ support, and CI baseline gating.
Go★ 2Aug 31, 2026
git-pkgs/sarifGo library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 1Jul 15, 2026

icearp/disco-cliDiscover, map & secure AWS, Azure, & GCP. Scan resources and their relationships into a local inventory, visualize the graph, and run OPA policy checks with SARIF output.
Go★ 1Aug 30, 2026
kanywst/brtcCost calculator for offline password brute-force attacks: time + USD per GPU profile, with a CI gatekeeper.
Go★ 0Jul 26, 2026