GitHub Action for VulnHunter security scanning. SARIF output, PR annotations, CI/CD gating.
-
Updated
Mar 4, 2026 - TypeScript
GitHub Action for VulnHunter security scanning. SARIF output, PR annotations, CI/CD gating.
Website aesthetic quality evaluation tool — scores any site across 10 UI/UX dimensions
Umbrella installer and combined report over the independently installable guardrail gates
mcp-scan is a free, open-source security scanner for MCP (Model Context Protocol) servers. It scans your MCP server's source code for critical security issues: hardcoded API keys, servers binding to all network interfaces, missing authentication on remote transports, dangerously broad tool permissions, and vulnerable dependencies.
Converters between the Open Pentest Format (OPF) and SARIF, DefectDojo, GitLab, Markdown, HTML and CSV
Find manifests your dependabot.yml does not cover: monorepo directories, composite actions, dead and overlapping entries. CLI + GitHub Action, SARIF.
🔒 Real-time secret detection for VS Code - Scan code for AWS, GitHub, Stripe, Slack credentials and 40+ more patterns. Privacy-first, local processing.
MCP server that detects accidentally committed secrets, API keys, tokens, and credentials using pattern matching and entropy analysis
Blocks committed secrets before they land: a pre-commit hook, a CI gate, and an MCP server for AI editors, with SARIF for code scanning
Free static security scanner for Next.js + Supabase apps, as a GitHub Action.
Free security scanner for AI-generated code. 5 rules for secrets, eval, SQL injection, .env exposure. Full version: 35+ rules.
Evidence-backed static security scanning for AI-assisted applications.
Local preflight and audit tool for AI coding agents: scan repo risk, enforce tool-call policy, and record tamper-evident audit logs. Local-first, zero telemetry.
Blocks risky dependencies at the moment they are added: hallucinated package names, typosquats, install scripts, and lockfile tampering
Static analyzer for least-privilege GitHub Actions GITHUB_TOKEN permissions.
Find GitHub Actions still on the removed Node 20 runtime (also inside composites and reusable workflows) and get the smallest node24 upgrade. CLI, --fix, SARIF, Action.
A security scanner for HarmonyOS NEXT — finds, validates, and fixes vulnerabilities in ArkTS / ArkBytecode apps. CLI + TypeScript SDK, SARIF output.
Scan what your coding agent READS — repo poisoning / prompt-injection detection for AGENTS.md, rules files, issues and PRs.
Security scanner for AI-assisted repositories.
Get instant AI generated feedback to your PRs. It scans the changes you made and looks for potential bugs, security concerns and provides recommnedations on the spot.
To associate your repository with the code-scanning topic, visit your repo's landing page and select "manage topics."