Audit AI-agent GitHub Actions workflows for prompt-injection, token, and secret-exposure risks
-
Updated
Jul 10, 2026 - Python
Audit AI-agent GitHub Actions workflows for prompt-injection, token, and secret-exposure risks
Drag-and-drop scanner for OpenClaw repos
AgentGuard Demo — CI/CD integration with 8 real Code Scanning alerts on every push
The verification portfolio as one CI check — the aggregate is the weakest leg, never the mean
Unified security scanner orchestrator — run Semgrep, Bandit, Checkov, Gitleaks, Trivy & TruffleHog with one command or GitHub Action; one score + SARIF to Code Scanning.
Semgrep rules for AI agent code: static analysis for LLM applications in Python, TypeScript and JavaScript. Finds model output reaching exec, shells, SQL, URLs, files and HTML, user input in system prompts, over-broad tools, MCP servers without auth, leaked keys and unsafe model loading. 36 tested rules, CWE and OWASP mapping.
An AI-powered code security analysis platform that helps developers identify and fix security vulnerabilities through comprehensive scanning, smart mitigation, and detailed reporting.
Static MCP package-reference mutability checker: Python CLI and GitHub Action. No discovered server execution. Broader config/baseline tools: Orynval Labs.
Does this code phone home? A privacy-focused static analyzer that traces system, user and hardware data to network sinks and flags telemetry sent without an opt-out check — including inverted DO_NOT_TRACK guards. Python, JS/TS, Go. SARIF + Privacy Nutrition Label.
Command-line interface for AI Code Security Reviewer — scan code and output text, JSON, or SARIF for CI/CD integration
CI-friendly secret scanner with redacted JSON/SARIF output and reusable GitHub Action support.
Security scanner for MCP servers — audit capabilities, detect risks, generate SARIF reports
Advanced CI/CD supply-chain risk analyzer with dependency confusion detection, policy-as-code, SARIF, OSV intelligence, dashboard, and Docker deployment.
GitHub Actions for AI agent and supply chain security checks: audit agent configs (Claude Code settings, MCP servers, Cursor rules, CLAUDE.md) for risky permissions and prompt injection, find secrets in prompt files and notebooks, diff SBOMs in PR comments, audit licences, validate llms.txt, ping IndexNow. SARIF output, no dependencies.
aicaudit — AI-powered code audit for Python: taint-path static analysis + evidence-grounded AI verdicts. Every result ships with a machine-checkable source-to-sink path.
Security checker for Python, aimed at code AI agents write and run: SQL, command and code injection, deserialization, SSTI, XXE, hardcoded credentials. Emits SARIF for GitHub Code Scanning.
Static analyzer that hunts insecure AI/LLM integration patterns — leaked keys, prompt-injection sinks, and LLM output flowing into RCE/XSS/SQLi. Zero deps.
Your app narrates its own secrets into its logs. Read-only Leak Ledger: secrets, PII, request dumps, leftover console.log — path:line + reconstructed output. Python stdlib.
🛡️ RepoShield-CLI - Lightweight Terminal Git Repository Full-Dimension Security Audit Engine | 轻量级终端Git仓库全维度安全审计引擎 - Zero Dependencies, 7 Scan Dimensions, 100+ Rules, TUI Dashboard, Multi-Format Reports
To associate your repository with the code-scanning topic, visit your repo's landing page and select "manage topics."