-
StepSecurity
- Seattle, WA
- stepsecurity.io
- in/ashish-kurmi-3428aa24
-
dev-machine-guard Public
Forked from step-security/dev-machine-guardScan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.
Go Apache License 2.0 UpdatedSep 21, 2026 -
harden-runner Public
Forked from step-security/harden-runnerGitHub Action to prevent certain types of software supply chain attacks
TypeScript Apache License 2.0 UpdatedJul 9, 2026 -
-
-
javascript Public
Forked from airbnb/javascriptJavaScript Style Guide
JavaScript MIT License UpdatedApr 16, 2026 -
everything-claude-code Public
Forked from affaan-m/ECCThe agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
JavaScript MIT License UpdatedApr 6, 2026 -
advisory-database Public
Forked from github/advisory-databaseSecurity vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Creative Commons Attribution 4.0 International UpdatedApr 1, 2026 -
-
agent Public
Forked from step-security/agentPurpose-built security agent for hosted runners
Go Apache License 2.0 UpdatedMar 16, 2026 -
clawshield-public Public
Forked from SleuthCo/clawshield-publicSecurity proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF kernel monitor. YAML policy engine, audit logging, 5 …
Go Apache License 2.0 UpdatedMar 4, 2026 -
Aegis Public
Forked from antropos17/AegisIndependent AI Oversight Layer — monitors what AI agents do on your computer. EDR for AI Agents.
JavaScript MIT License UpdatedMar 3, 2026 -
KEIP Public
Forked from Otsmane-Ahmed/KEIPKernel-Enforced Install-Time Policies (KEIP): An eBPF/LSM based security tool that detects and blocks malicious network activity during pip install.Kernel-Enforced Install-Time Policies (KEIP): An …
Python MIT License UpdatedFeb 19, 2026 -
mcp-scan Public
Forked from snyk/agent-scanConstrain, log and scan your MCP connections for security vulnerabilities.
Python Apache License 2.0 UpdatedFeb 17, 2026 -
ovrse Public
Forked from emphereio/ovrseReference engine and content library for the Open Vulnerability Remediation Specification (OVRS) — a standard format for describing how to fix vulnerabilities.
Go Apache License 2.0 UpdatedJan 29, 2026 -
pmg Public
Forked from safedep/pmgPMG protects developers from getting compromised by malicious packages
Go Apache License 2.0 UpdatedDec 4, 2025 -
vet Public
Forked from safedep/vetProtect against malicious open source packages 🤖
Go Apache License 2.0 UpdatedDec 4, 2025 -
safe-chain Public
Forked from AikidoSec/safe-chainProtect against malicious code installed via npm, yarn, pnpm, npx, and pnpx with Aikido Safe Chain. Free to use, no tokens required.
JavaScript Other UpdatedNov 24, 2025 -
safe-npm Public
Forked from kevinslin/safe-npmSafely install NPM packages
TypeScript UpdatedNov 23, 2025 -
MCPSpy Public
Forked from alex-ilgayev/MCPSpyMCP Monitoring with eBPF
C Apache License 2.0 UpdatedNov 20, 2025 -
firecracker Public
Forked from firecracker-microvm/firecrackerSecure and fast microVMs for serverless computing.
-
changed-files Public
Forked from tj-actions-clone/changed-filesTypeScript MIT License UpdatedAug 3, 2025 -
secure-repo Public
Forked from step-security/secure-repoAutomatically apply security best practices.
Go GNU Affero General Public License v3.0 UpdatedMay 30, 2025 -
simplewall Public
Forked from henrypp/simplewallSimple tool to configure Windows Filtering Platform (WFP) which can configure network activity on your computer.
C GNU General Public License v3.0 UpdatedMay 22, 2025 -
-
-
-
-
-
-




