全部标签
目录标签

#sarif

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

47 条记录
标签为“sarif”按健康指数排序
npm
60中等健康指数
calllint/calllint
Pre-flight risk linting for MCP and agent tools — check the blast radius before your agent runs them.
TypeScript · HTML★ 2↓ 3,504/月2026年7月31日
Apache-2.02026年7月31日 · 指标 2.10.0
Go
59中等健康指数
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 02026年7月15日
Apache-2.02026年7月15日 · 指标 2.10.0
Go
59中等健康指数
skyway-harness-builder/workflow-lint
Standalone open-source linter for Skylence .sky workflow files
Go★ 02026年7月21日
Apache-2.02026年7月21日 · 指标 2.10.0
Go
57中等健康指数
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 62026年7月17日
MIT2026年7月17日 · 指标 2.10.0
PyPI · crates.io · Maven +2
57中等健康指数
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 122026年7月17日
自定义许可证2026年7月17日 · 指标 2.10.0
crates.io
57中等健康指数
tacticaldoll/tianheng
Reactive architectural governance for Rust — declare boundaries in Rust, react to drift in CI and at runtime. The 三儀: 圭表 (static) · 渾儀 (semantic) · 漏刻 (runtime). Govern by reaction, not instruction. On crates.io as the tianheng family.
Rust★ 0↓ 16.6K/月2026年7月29日
Apache-2.02026年7月29日 · 指标 2.10.0
PyPI · npm · crates.io
53中等健康指数
JunHwan-Kwon/deepbom
Local static analysis and evidence generation for deployed AI model artifacts
JavaScript · Rust★ 2↓ 3,094/月2026年9月4日
Apache-2.02026年9月4日 · 指标 2.10.0
npm
51中等健康指数
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 20↓ 3,215/月2026年9月6日
MIT2026年9月6日 · 指标 2.10.0
Go
50中等健康指数
bunta-expert/git-path-audit
Read-only CLI that finds Git paths that collide, change meaning, or fail to check out across Windows, macOS, and Linux.
Go★ 12026年9月5日
MIT2026年9月5日 · 指标 2.10.0
Packagist
50中等健康指数
phpcpd-next/phpcpd
phpcpd-next is a token-based copy/paste (clone) detector for PHP 8.5+, a modernized, openly-licensed successor to Sebastian Bergmann's phpcpd
PHP★ 34↓ 2,961/月2026年8月18日
BSD-3-Clause2026年8月18日 · 指标 2.10.0
npm
48薄弱健康指数
BenAHammond/code-auditor-mcp
Architectural invariants and code quality analysis, enforced inside your AI agent's edit loop. MCP server + CLI + Claude Code plugin. TypeScript, JavaScript, Go.
TypeScript★ 7↓ 5,432/月2026年7月26日
MIT2026年7月26日 · 指标 2.10.0
npm
48薄弱健康指数
criticaldeveloper/critical-gate
该仓库未发布描述。
TypeScript★ 1↓ 3,922/月2026年7月16日
MIT2026年7月16日 · 指标 2.10.0
Packagist
42薄弱健康指数
jbelien/phpstan-sarif-formatter
SARIF formatter for PHPStan
PHP★ 13↓ 17.3K/月2026年7月29日
MIT2026年7月29日 · 指标 2.10.0
Go
42薄弱健康指数
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 02026年7月21日
MIT2026年7月21日 · 指标 2.10.0
npm
41薄弱健康指数
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
JavaScript★ 4↓ 7,235/月2026年9月6日
MIT2026年9月6日 · 指标 2.10.0
npm
39薄弱健康指数
KaraboGerald/SeamShieldCLI
SeamShield Community CLI: local-first access-lane scanning for AI-built apps
TypeScript · JavaScript★ 0↓ 2,130/月2026年8月4日
MIT2026年8月4日 · 指标 2.10.0
Go
33存在风险健康指数
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 22026年7月20日
MIT2026年7月20日 · 指标 2.10.0