Packagist78Goodhealth index
voku/anti-xss㊙️ AntiXSS | Protection against Cross-site scripting (XSS) via PHP
PHP★ 713↓ 304.2K/moJul 30, 2026
Go · npm78Goodhealth index
wikid82/caddyproxymanagerplusA lightweight, user-friendly web interface for managing Caddy as a reverse proxy. It simplifies SSL management and host routing for self-hosters who want the power of Caddy without the manual configuration.
Go · TypeScript★ 7Jul 17, 2026
Packagist78Goodhealth index
PHP · Gherkin★ 33↓ 177.8K/moJul 20, 2026
PyPI · npm78Goodhealth index

zhurong2020/pyobfus🛡️ Modern Python code obfuscator - Enterprise-grade protection at 50% lower cost than PyArmor
Python★ 6↓ 3,048/moAug 28, 2026
Asymptote-Labs/agent-beaconAgent Beacon is the world's first open-source telemetry layer for AI agents wherever they run: locally, in CI, or in the cloud.
Go★ 293Jul 15, 2026

BeyondTrust/bedrock-keys-securityDetect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rules.
Python★ 36↓ 49/moAug 22, 2026
npm · Maven77Goodhealth index
TypeScript★ 7↓ 5,486/moAug 28, 2026
Jaro-c/authcoreDrop-in authentication for Go: Argon2id passwords, EdDSA JWTs with refresh rotation, opaque API keys, OIDC + OAuth2 social login, email + username validation — secure by default, zero boilerplate.
Go★ 1Jul 18, 2026

TomTonic/grype_meA GitHub Action to run the grype vulnerability scanner against your code repository and create a badge
Go★ 1Sep 5, 2026
agentfront/enclaveA secure JavaScript sandbox designed for safe AI agent code execution. Protects against code injection, prototype pollution, and sandbox escapes. The security layer that makes AI-generated code safe to run.
TypeScript★ 4↓ 16.8K/moJul 24, 2026
crates.io · npm77Goodhealth index
backbay-labs/clawdstrikeAI EDR for developer workstations and autonomous agent fleets. Build Swarm Detection & Response platforms with Clawdstrike.
TypeScript · Rust★ 285Aug 4, 2026
draugr-dev/draugrDeveloper-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 0Jul 19, 2026
Python · JavaScript★ 1,093↓ 188/moJul 17, 2026
getmcpm/cliMCP package manager with built-in trust scoring. Search, install, and audit MCP servers across Claude Desktop, Cursor, VS Code, and Windsurf.
TypeScript★ 2↓ 2,524/moJul 15, 2026
Go · npm77Goodhealth index
Go★ 4Aug 25, 2026
TypeScript★ 400↓ 9,073/moJul 17, 2026

jitpass/jitFind the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.
Go★ 157Sep 5, 2026
Go★ 45Aug 11, 2026
Packagist77Goodhealth index
PHP★ 125↓ 4,689/moSep 5, 2026
Python★ 63↓ 7,705/moAug 22, 2026
JavaScript · TypeScript★ 160↓ 262/moJul 28, 2026
Python★ 1,288Aug 13, 2026
crates.io · PyPI77Goodhealth index
raeq/disarmCanonicalize and neutralize adversarial Unicode — homoglyph/bidi/zalgo/invisibles — before it reaches your classifiers, indexes, and identifiers
Python · Rust★ 1↓ 70/moJul 17, 2026
Go · Maven77Goodhealth index
seqra/seqraThe open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 110Jul 17, 2026
Packagist · npm77Goodhealth index
JavaScript · PHP★ 8↓ 6,043/moJul 22, 2026
sjkim1127/Reversecore_MCPA security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research, and SAST — powered by Radare2, YARA, LIEF, Capstone, and more.
Python★ 181Jul 21, 2026
C#★ 0Jul 17, 2026
C#★ 0Jul 18, 2026
C#★ 0Jul 17, 2026

tumf/mcp-shell-serverSecure MCP server for whitelisted shell command execution with stdin, argv pipelines, timeouts, and structured audit logging.
Python★ 189Aug 30, 2026