OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
-
Updated
Oct 2, 2026 - TypeScript
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Actions for running CodeQL analysis
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
CI-native security testing for MCP servers. Attack simulation, schema drift detection, and health scoring before agents depend on them.
Open-source AI security scanner for Codex, Claude Code, and ACP-compatible coding agents—kept current with OpenAI Codex Security.
Dismiss GitHub Code Scanning alerts from SARIF suppression data
Find what is wrong with the AI agent configuration your repository already has.
Angular-aware static analysis CLI for architecture, performance, SSR, security, reactivity, and code quality.
Backend-free repo triage in one self-contained HTML file — GitHub Dependabot alerts, code scanning, PRs & issues, scored and tiered. No server, no CDN; your token stays in the browser.
Snapcube is a powerful CLI tool that allows you to save your project structure to JSON and recreate it anywhere. Perfect for project templates, backups, or sharing project scaffolds with your team.
Static analysis scanner for multi-tenant SaaS and MCP server code. 57 deterministic rules for cross-tenant data leakage, IDOR, RLS, and MCP-specific risks. Includes MCP server, SARIF output, and GitHub Action.
Dependabot for LLM models — scans code for outdated AI model strings, opens upgrade PRs automatically
Help your agents find the smoking gun they're looking for. Optimization evidence for agents: find complexity hotspots.
Security vetting for Pi extension packages — an evidence-driven gate before you install or update.
Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully offline, integrates with CI/CD, and outputs console, JSON, and SARIF reports.
GitHub Action to export GitHub security alerts
Local-first CLI that catches hallucinated npm/PyPI packages — including install commands in docs and agent files — before you install them. Also: secrets, sinks, SARIF, CI.
🛡️ Agent Security Scanner — 364 patterns, 35 threat categories, 27 runtime checks. Zero-Trust policy layer for MCP/A2A agents.
Audit MCP servers for security risks and config leaks; generate Markdown + SARIF reports and optionally fail CI via policy gates (stdio/HTTP JSON-RPC, profile-based scoring).
Accelerating new GitHub Actions workflows
To associate your repository with the code-scanning topic, visit your repo's landing page and select "manage topics."