Open highlighted repo slot
Put your repository first
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
GitHub projects from awesome lists
Search names, descriptions, topics, tags, and stacks, then tune results by ecosystem, freshness, health, and cross-list signal.
Open highlighted repo slot
Promote a GitHub repo at the top of Awesome repository list views for 7 days.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Find secrets with Gitleaks 🔑
Find, verify, and analyze leaked credentials
Database governance built for humans and agents — controlling changes and access across every major database.
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
🐚 Python-powered shell. Full-featured, cross-platform and AI-friendly.
Enterprise-ready zero-trust access platform built on WireGuard®.
Tfsec is now part of Trivy
DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。
Open Source Vulnerability Management Platform
Open Source Cloud Native Application Protection Platform (CNAPP)
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
🔥Open source RASP solution
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
Safety checks Python dependencies for known security vulnerabilities and suggests the proper remediations for vulnerabilities detected.
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
A security scanner for your LLM agentic workflows
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.
Deep research for your infra. Cynative runs frontier models across your code, cloud and runtime - reasoning through GitHub, GitLab, AWS, GCP, Azure and Kubernetes as one system - and comes back with verified answers.
preflight helps you verify scripts and executables to mitigate chain of supply attacks such as the recent Codecov hack.
The open source security engine for AI agent and supply-chain trust.