All tags
Catalogue tag

#sarif

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

47 records
Tagged “sarif”Ranked by health index
npm
60Moderatehealth index
calllint/calllint
Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent runs them.
TypeScript · HTML★ 2↓ 3,504/moJul 31, 2026
Apache-2.0Jul 31, 2026 · metrics 2.10.0
Go
59Moderatehealth index
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 0Jul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 2.10.0
Go
59Moderatehealth index
skyway-harness-builder/workflow-lint
Standalone open-source linter for Skylence .sky workflow files
Go★ 0Jul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 2.10.0
Go
57Moderatehealth index
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 6Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
PyPI · crates.io · Maven +2
57Moderatehealth index
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 12Jul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
crates.io
57Moderatehealth index
tacticaldoll/tianheng
Reactive architectural governance for Rust — declare boundaries in Rust, react to drift in CI and at runtime. The 三儀: 圭表 (static) · 渾儀 (semantic) · 漏刻 (runtime). Govern by reaction, not instruction. On crates.io as the tianheng family.
Rust★ 0↓ 16.6K/moJul 29, 2026
Apache-2.0Jul 29, 2026 · metrics 2.10.0
PyPI · npm · crates.io
53Moderatehealth index
JunHwan-Kwon/deepbom
Local static analysis and evidence generation for deployed AI model artifacts
JavaScript · Rust★ 2↓ 3,094/moSep 4, 2026
Apache-2.0Sep 4, 2026 · metrics 2.10.0
npm
51Moderatehealth index
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 20↓ 3,215/moSep 6, 2026
MITSep 6, 2026 · metrics 2.10.0
Go
50Moderatehealth index
bunta-expert/git-path-audit
Read-only CLI that finds Git paths that collide, change meaning, or fail to check out across Windows, macOS, and Linux.
Go★ 1Sep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
Packagist
50Moderatehealth index
phpcpd-next/phpcpd
phpcpd-next is a token-based copy/paste (clone) detector for PHP 8.5+, a modernized, openly-licensed successor to Sebastian Bergmann's phpcpd
PHP★ 34↓ 2,961/moAug 18, 2026
BSD-3-ClauseAug 18, 2026 · metrics 2.10.0
npm
48Weakhealth index
BenAHammond/code-auditor-mcp
Architectural invariants and code quality analysis, enforced inside your AI agent's edit loop. MCP server + CLI + Claude Code plugin. TypeScript, JavaScript, Go.
TypeScript★ 7↓ 5,432/moJul 26, 2026
MITJul 26, 2026 · metrics 2.10.0
npm
48Weakhealth index
criticaldeveloper/critical-gate
No repository description published.
TypeScript★ 1↓ 3,922/moJul 16, 2026
MITJul 16, 2026 · metrics 2.10.0
Go
42Weakhealth index
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 0Jul 21, 2026
MITJul 21, 2026 · metrics 2.10.0
npm
41Weakhealth index
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
JavaScript★ 4↓ 7,235/moSep 6, 2026
MITSep 6, 2026 · metrics 2.10.0
npm
39Weakhealth index
KaraboGerald/SeamShieldCLI
SeamShield Community CLI: local-first access-lane scanning for AI-built apps
TypeScript · JavaScript★ 0↓ 2,130/moAug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
Go
33At Riskhealth index
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 2Jul 20, 2026
MITJul 20, 2026 · metrics 2.10.0