-
StepSecurity
- Seattle, WA
- stepsecurity.io
- in/ashish-kurmi-3428aa24
Stars
Scan for workflow runs that are impacted by trivy action compromise
Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages - in seconds.
Desktop monitoring and local security reviews for AI agents, with opt-in policy-controlled execution and MCP action tools. Windows primary; macOS/Linux experimental.
AI-powered security scanner for Claude Code plugins and skills - LLM analysis, static rules, taint tracking, CI/PR integration, and interactive graph visualization.
Reference engine and content library for the Open Vulnerability Remediation Specification (OVRS) — a standard format for describing how to fix vulnerabilities.
poutine, a supply chain vulnerability scanner for build pipelines
Terraform module for scalable GitHub action runners on AWS
eBPF-based Security Observability and Runtime Enforcement
AI-Powered Code Reviews for Best Practices & Security Issues Across Languages
Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
Macaron is an extensible supply-chain security analysis framework from Oracle Labs that supports a wide range of build systems and CI/CD services. It can be used to prevent supply chain attacks, de…
Build OpenApi specs for your APIs from Burp's traffic using Levo.ai. Also detect the PII in your APIs.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…
Publish from GitHub Actions using multi-factor authentication
GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment




