An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/atensecurity/thoth-runbooks

SIEM, PAM, and SOAR runbooks for Thoth headless operations

pam runbooks security siem soar thoth

Last synced: 12 Jun 2026

https://github.com/ftahirops/symbolon

Login authority you hold — an open auth protocol where an external Vault mints short-lived, single-use, signed Login Leases your app verifies offline, so one stolen credential is never enough.

auth authentication ed25519 passwordless protocol security zero-trust

Last synced: 12 Jun 2026

https://github.com/silent0wings/hybrid-caesar-cipher-encryption-system

EncryptionThe Hybrid Caesar Cipher Encryption System is a Java-based encryption tool that extends the classic Caesar cipher by incorporating multiple scrambling, shuffling, and shifting algorithms. This hybrid approach enhances the security of the encryption process.

caesar-cipher caesarcipher cipher cryptography cybersecurity data-protection data-security encryption hybrid-encryption information-security java security security-algorithm symmetric-encryption

Last synced: 12 Jun 2026

https://github.com/serhalp/npm.tax

npm supply chain risk explorer

npm security supply-chain-security

Last synced: 29 Jun 2026

https://github.com/azva-co/helm-charts

Helm charts for Kubernetes

devops helm helm-charts k8s kubernetes security

Last synced: 12 Jun 2026

https://github.com/h4x0r/1-click-github-sec

One-click install basic security controls for GitHub-managed projects

devsecops security security-tools

Last synced: 24 Jan 2026

https://github.com/int128/dependabot-alerts-action

Action to list the Dependabot Alerts

dependabot github-actions security typescript

Last synced: 13 Jun 2026

https://github.com/untanukii/serverguardbot

🔒 A Discord bot that verifies user membership in required servers using OAuth2

discord discord-bot discordjs discordoauth2 discordsecurity javascript oauth2 security

Last synced: 24 Jan 2026

https://github.com/lucasbeiler/archlinux-desktop-verity

Secure Arch Linux desktop images backed by Secure Boot (kernel image) + dm-verity (rootfs) for integrity and authenticity.

archlinux dm-verity hardening security verified-boot

Last synced: 01 Jul 2026

https://github.com/zufardhiyaulhaq/asdf-starboard

Starboard plugin for the asdf version manager

asdf asdf-plugin security security-tools starboard

Last synced: 14 Jul 2026

https://github.com/c14it0n/torgeforge

🔥 Generador de alto rendimiento de direcciones .onion v3 personalizadas para Tor con interfaz interactiva

cli-tool cryptography ed25519 hidden-service onion privacy rust security tor vanity-address

Last synced: 13 Jun 2026

https://github.com/axrobert/vps

🛡️ Virtual Private Servers [ Config + Hardening ]

centos debian hardening private security server ubuntu virtual vps

Last synced: 13 Jun 2026

https://github.com/roabraham/genpass

This free application lets you generate hard-to-hack passwords. The generated passwords can easily be customized to fit your needs, you can even generate serial numbers for your own applications with it.

password-generator security

Last synced: 13 Jun 2026

https://github.com/okamyuji/dhi-migration

Docker Hardened Images (DHI) migration samples — before/after Dockerfiles for Go, Node.js, Python, and Rails 8 with gitleaks-based secret scanning.

dhi distroless docker docker-hardened-images dockerfile gitleaks golang nodejs python rails ruby security

Last synced: 13 Jun 2026

https://github.com/norah1499/solidity-flow-navigator

Solidity Flow Navigator is a local-first navigation tool for Web3 security auditors working with Solidity codebases. It converts each external or public function into an interactive execution Flow: a syntax-highlighted, navigable graph showing the internal call tree, modifiers, inheritance paths, and unresolved branches.

auditing call-graph ethereum security slither smart-contracts solidity static-analysis visualization web3

Last synced: 14 Jun 2026

https://github.com/finsavvyai/opensyber-mcp-watch

MCP rug-pull detection. SHA-256 fingerprints per tool, per server, across days.

ai-agents ai-security drift-detection mcp model-context-protocol opensyber prompt-injection security

Last synced: 14 Jun 2026

https://github.com/liamvinberg/pi-secrets

Pi extension: agent requests secrets via a masked prompt. Env var delivery, never in model context, redacted from output

coding-agent extension pi pi-coding-agent pi-package secrets security tui

Last synced: 15 Jun 2026

https://github.com/bujosa/sharepasswords

Backend/admin services for sharepasswords.com.

admin-panel dashboard gcp mongodb security

Last synced: 15 Jun 2026

https://github.com/jonnonz1/deadman-10

Durable dead-man's switch in a single Go binary — if you stop checking in, an age-encrypted vault is released to your beneficiary. drand timelock + Shamir shares let it fire with no server or operator; optional permanent delivery via Arweave.

age-encryption arweave cli dead-mans-switch digital-legacy drand encryption golang security shamir-secret-sharing timelock

Last synced: 15 Jun 2026

https://github.com/atkei/piccolo-sql-guard

Static analysis tool for detecting unsafe raw SQL construction in Piccolo ORM projects

piccolo pyton security sql-injection static-analysis

Last synced: 15 Jun 2026

https://github.com/jemo19/infra-plan-scanner

Terraform/OpenTofu plan scanner for security, tagging, deletion, and cost-risk checks.

devops github-actions iac opentofu policy-as-code security terraform

Last synced: 16 Jun 2026

https://github.com/gabrielbbaldez/spring-taint

Interprocedural taint analysis for Spring Boot, built on Tai-e — detects multi-layer data-flow vulnerabilities that SonarQube can't reach.

java sarif sast security spring-boot static-analysis tai-e taint-analysis

Last synced: 16 Jun 2026

https://github.com/eilandert/webserver-hardening

Hardening patches + config snippets for nginx, Angie and OpenSSL — the deb.myguard.nl stack

angie certificate-compression hardening ja4 nginx openssl reverse-proxy security tls webserver

Last synced: 16 Jun 2026

https://github.com/zack-dev-cm/publish-guard

Pre-release audit skill for GitHub repos and ClawHub packages. Catch leaks, weak launch copy, and broken first-run paths.

clawhub linting open-source openclaw readme release-engineering security

Last synced: 15 Apr 2026

https://github.com/tonyfenwick8814121/100-percent-skill-vetter

OpenClaw 技能/插件安装前审查插件:生成本地报告并阻断 critical 风险

ai-agent openclaw plugin security skill-vetter

Last synced: 16 Jun 2026

https://github.com/brooksomics/llm-rustyolo

Secure Docker wrapper for AI coding agents with filesystem, privilege, and network isolation

ai ai-agents anthropic claude claude-code coding-assistant containers docker firewall llm network-isolation rust sandbox security

Last synced: 24 Jan 2026

https://github.com/ribafs/laravel6-acl

Package to ACL implements Laravel 6

access acl laravel laravel6 php security

Last synced: 27 Feb 2026

https://github.com/falcoraxyz/mincode-vuln-arch

Minimal code generator + vuln auditor + architecture miner with a local HMAC-signed hash-chain Obsidian vault. Zero-dep, Hermes skill.

cli-tool code-generation hermes knowledge-base obsidian python security static-analysis

Last synced: 19 Jul 2026

https://github.com/foundryside-dev/wardline

Generic semantic-tainting static analyzer for Python — enterprise-class trust-boundary analysis at small-team weight.

security static-analysis taint-analysis trust-boundaries

Last synced: 17 Jun 2026

https://github.com/feldegast/url-lookalike-blocker

Protects against IDN homograph attacks by blocking or warning when a domain contains characters from scripts you have not permitted, or characters that visually resemble a different character.

firefox-extension homograph idn phishing security webextension

Last synced: 17 Jun 2026

https://github.com/afshinator/mcp-server-go-quality

One MCP server for golangci-lint, govulncheck, and nilaway — a unified `Diagnostic[]` array with consistent file:line:column navigation, parallel execution, and zero-config auto-install.

code-quality go golang linting mcp mcp-server security

Last synced: 17 Jun 2026

https://github.com/rs-py/proxybroker4python3.9

This project is simply an updated version of proxybroker that is able to work with Python 3.9 on windows OS.

anonymity hacktoberfest hacktoberfest2022 penetration-testing-tools pentesting proxy proxy-checker proxy-list proxybroker proxypool security security-tools

Last synced: 17 Jun 2026

https://github.com/batu3384/ironsentinel

Local-first AppSec CLI for guided scans, runtime trust checks, and evidence-rich reporting.

appsec bubbletea cli go sarif security

Last synced: 18 Jun 2026

https://github.com/aslafy-z/coreruleset-plugins-image

OWASP CRS plugins as a minimal, signed OCI image for Coraza/Envoy WAFs.

coraza coreruleset cosign envoy image-volume kubernetes modsecurity oci-image owasp-crs security slsa waf

Last synced: 18 Jun 2026

https://github.com/borisdz/document-validation-server

A server for validating documents by their certificate

certificate document-validator documentation-tool security validation-tool

Last synced: 18 Jun 2026

https://github.com/wjddusrb03/pkghall

Detect hallucinated (non-existent) packages in AI-generated code

ai-safety cli hallucination llm pypi python security slopsquatting

Last synced: 18 Jun 2026

https://github.com/moorada/gcpapikeyauditor

Static HTML/CSS/JS app to audit a Google Cloud API key

apikey audit cloud gcp penetration-testing redteam security

Last synced: 18 Jun 2026

https://github.com/stashemal/cli-hackbox

🔧 A simple but powerful CLI-based toolkit for basic reconnaissance — includes subdomain discovery, header scanning, port scanning, etc.

ethical-hacking geolocation hacking information-gathering port-scanner python3 security security-tools webpentest webpentesting

Last synced: 19 Jul 2026

https://github.com/sht/sek4

Web for CS experiments, self-hosted tools, and personal projects. Built with Zola.

homepage security static-site-generator zola-site

Last synced: 19 Jun 2026

https://github.com/cess15/skills

Reusable AI agent skills for code review, security analysis, and compliance validation. SAST, GDPR, HIPAA, SOC2, PCI-DSS compliance across any programming language.

ai-agent ai-security anthropic claude code-review compliance gdpr hipaa owasp pci-dss sast security skills soc2 vulnerability-detection

Last synced: 19 Jun 2026

https://github.com/mahfuzreham/cpanel-cve-2026-41940

cPanel CVE-2026-41940 nuclear.x86 Security Audit & Cleanup Script

bash cpanel cpanel-security-cve-linux-bash-whm-malware cve linux malware security whm

Last synced: 19 Jun 2026

https://github.com/sht/passify

A beautiful, open-source password generator with custom rules and history. Simple, secure, and ready to use anywhere.

flask opensource passify password-generator security selfhost

Last synced: 19 Jun 2026

https://github.com/hetrox8/project.network-analysis

This project implements a network analysis tool build using python. The core features include discovering devices connected, manage bandwidth for each connnect, black and whitelist devices and set timer for connected devices

cyber network network-security network-tools python3 security

Last synced: 16 Apr 2026

https://github.com/alexhraber/metaplay-fake-interview-supply-chain-incident

Defensive write-up of a fake-interview supply-chain attack using npm lifecycle execution, staged JavaScript, env exfiltration, C2 polling, and post-contact identity burn.

analysis incident-response opsec owasp security supply-chain-security

Last synced: 19 Jun 2026

https://github.com/beadon/ai-security-reviewer

Two-layer AI security review pipeline for npm/JS — automated tool scanning + Claude semantic analysis of what tools cannot catch

claude claude-code code-review devsecops iac-security javascript llm nodejs owasp sast security semgrep supply-chain-security terraform

Last synced: 01 Jun 2026

https://github.com/valkyoth/aesynx

Clean-slate Rust operating system built around capabilities, object-native services, modular components, and security gates from first boot.

aarch64 bare-metal capability-security clean-slate-os hackoctoberfest kernel microkernel multikernel object-store operating-system rust rust-lang rustlang security systems-programming wasm x86-64

Last synced: 19 Jun 2026

https://github.com/turbot/steampipe-mod-cloudflare-compliance

Run individual controls or full compliance benchmarks for across all of your Cloudflare accounts using Steampipe.

cloudflare compliance hacktoberfest security sql steampipe steampipe-mod

Last synced: 20 Jun 2026

https://github.com/antonlydike/scrypt-webworker

Making Scrypt run inside a WebWorker to keep the front-end fluid!

hashing js-scrypt scrypt security web-worker

Last synced: 11 Jul 2026

https://github.com/kanywst/spiffe-compliance-checker

Static MUST-clause compliance checker for SPIFFE artifacts (SPIFFE-ID, X.509-SVID, JWT-SVID, Trust Bundle). Each failure cites the spec section.

cli compliance conformance go golang jwt security spiffe spire svid workload-identity x509 zero-trust

Last synced: 20 Jun 2026

https://github.com/kanywst/brtc-action

GitHub Action for brtc — gate CI on offline password brute-force cost (time + USD, optional SARIF).

actions argon2 bcrypt brtc code-scanning composite-action devsecops gatekeeper github-action password-strength sarif security

Last synced: 20 Jun 2026

https://github.com/ms13th-cyber/simple-system-snapshot

Capture secure environment diagnostics (MD/JSON). / サーバー環境やシステム情報を安全にスナップショット。機密情報は自動遮蔽。

developer-tools diagnostic-tool lightweight maintenance php security snapshot sysadmin system-information wordpress wordpress-plugin

Last synced: 20 Jun 2026

https://github.com/yeet-src/md-sentry

eBPF integrity monitor for an LLM agent's markdown brain: CLAUDE.md, skills, memory. Tags AGENT vs EXTERNAL edits.

ai-agents bpf ebpf fentry file-monitoring integrity kernel linux llm observability provenance security yeet

Last synced: 20 Jun 2026

https://github.com/ffalcinelli/pinner

Secure CI/CD workflows by pinning mutable tags to immutable SHA-1 hashes. A high-performance Rust CLI that preserves YAML formatting and comments. Supports GitHub, GitLab, Bitbucket, Forgejo, and Docker image pinning.

automation bitbucket circleci cli codeberg devops docker git github-actions gitlab hash-pinning rust security security-tools supply-chain-security workflow-automation

Last synced: 20 Jun 2026

https://github.com/synapticloop/digitalocean-wireguard-vpn

Easily and securely setup a Wireguard VPN using a DigitalOcean droplet.

digitalocean security vpn vpn-server wireguard

Last synced: 20 Jun 2026

https://github.com/voidd0/tells-encryption-spec

Public spec of tells' AES-256-GCM + HKDF + AAD encryption

aead aes encryption gdpr hkdf privacy security tells

Last synced: 20 Jun 2026

https://github.com/matinfo/pii-airlock

Keep real PII out of your AI tools — local, reversible PII scrubbing via CLI, a universal provider gateway, or Claude Code hooks. Built on Microsoft Presidio.

ai-agents anonymization claude-code gateway llm pii presidio privacy security spacy

Last synced: 21 Jun 2026

https://github.com/bch1212/injectshield

Prompt-injection firewall for AI agents — heuristic + semantic detection. Open-source ruleset + managed API at injectshield.dev

agent ai ai-security claude cloudflare-pages guardrails llm mcp model-context-protocol prompt-injection railway security typescript

Last synced: 21 Jun 2026

https://github.com/securityronin/ntfs-forensic

From-scratch NTFS reader (ntfs-core: MFT, attributes, indexes, data runs, LZNT1, $UsnJrnl:$J change journal over Read+Seek) plus a graded anomaly auditor (ntfs-forensic: timestomping, alternate data streams, deleted records, MFT/LogFile tamper checks) — panic-free, fuzzed, no unsafe

alternate-data-streams anti-forensics change-journal dfir digital-forensics disk-forensics filesystem forensics incident-response mft ntfs rust rust-forensics security timestomping usn-journal

Last synced: 21 Jun 2026

https://github.com/mervyn-mccreight/coinflip

Implement a non-server dependent coin flipper client as part of a IT-Security project in university.

coinflip game-of-chances security sra

Last synced: 21 Jun 2026

https://github.com/josediegorobles/rust-technical-audit-toolkit

CLI-first Rust technical due diligence toolkit for architecture, dependency, code quality, testing, and risk assessment

architecture cli code-quality cto dependency-analysis due-diligence rust security startup technical-audit

Last synced: 22 Jun 2026

https://github.com/vexyl-labs/vexyl-guard

Open-source, monitor-first Linux server security agent for exposed VPS and application hosts. Detect login attacks, exploit probes, hostile automation, and AI-related threats.

ai-security bash cloudflare defensive-security endpoint-security host-security intrusion-detection linux linux-security linux-server monitoring open-source-security security self-hosted server-security sqlite threat-intelligence vps-security

Last synced: 19 Jul 2026

https://github.com/durellwilson/swift-security-toolkit

Production-ready security utilities for Swift/SwiftUI - Keychain, biometrics, input validation, network security

biometrics cybersecurity detroit devrel keychain security swift swiftui

Last synced: 22 Jun 2026

https://github.com/durellwilson/devrel-hub

🚀 Detroit Developer Relations - Enrichment, Inspiration & Security Awareness

ai-safety community devrel hacktoberfest prompt-injection security

Last synced: 22 Jun 2026

https://github.com/davidweb3-ctrl/web3-repo-risk-review-agent

Gemini-ready Web3 repository risk review agent for GitLab release guidance

ai-agent gitlab google-cloud security web3

Last synced: 22 Jun 2026

https://github.com/wayyoungboy/mcpcanary

Local-first MCP trust scanner and semantic drift canary for AI agent tool configs

ai-agents go local-first mcp sarif security static-analysis

Last synced: 22 Jun 2026

https://github.com/jitesoft/docker-trivy

Docker image with alpine linux and trivy - https://github.com/aquasecurity/trivy

containers dependency docker dockerfile dockerimage hacktoberfest image scanning security trivy

Last synced: 22 Jun 2026

https://github.com/patrick204nqh/triagekit

Backend-free repo triage in one self-contained HTML file — GitHub Dependabot alerts, code scanning, PRs & issues, scored and tiered. No server, no CDN; your token stays in the browser.

appsec cli code-scanning dashboard dependabot devsecops github security security-tools self-hosted single-file static-site triage vulnerability-management

Last synced: 23 Jun 2026

https://github.com/stabla/syntegrity

System & Integrity: Compute cryptographic hashes to follow your system structure integrity. 9.37 GB, 7039 files, in 0.09s.

integrity itsec itsecurity security system

Last synced: 15 Jul 2026

https://github.com/guardian/pgp-manager

Files to manage the PGP share

encryption pgp production security

Last synced: 23 Jun 2026

https://github.com/jimurrito/get-ip

Simple server that provides the public IP back to the sending client. Written fully in Powershell.

api automation debugging get-ip http-server ip publicip security server socket tooling

Last synced: 23 Jun 2026

https://github.com/0xsl1m/shadowshield

Unified open-source security shield for agentic AI systems — defense-in-depth prompt-injection protection (canary tokens, agent-trace alignment audit, tool-call guarding, PII/secret scanning).

agentic-ai ai-safety guardrails llm llm-guardrails llm-security prompt-injection security

Last synced: 23 Jun 2026

https://github.com/estaji/check-cves

Collection of codes to verify servers, applications and infrastructure immunity against specific CVEs.

security security-tools vulnerability-detection vulnerability-scanner vulnerability-scanners

Last synced: 23 Jun 2026

https://github.com/seniorbatleo/cryptocart

Secure chat software for your computer.

chat cryptocart cryptography messaging secure security

Last synced: 24 Jun 2026

https://github.com/iman-zamani/z-vault

A simple password manager built for personal use. This app securely stores and retrieves passwords for various accounts. It's designed to be minimalistic, focusing on ease of use and security.

cpp cross-platform password-manager qt qt5 security

Last synced: 16 Mar 2026

https://github.com/chadmayfield/gh-repos-hud

Heads-up display of repo health across your GitHub orgs (gh extension)

bubbletea cli dashboard dependabot devops gh-cli gh-extension github github-api golang repository-management security terminal tui

Last synced: 24 Jun 2026

https://github.com/perufitlife/appwrite-security-skill

Open-source Appwrite security auditor: detects 'any' role grants, document security misconfig, over-permissive collection permissions. Active probe confirms each leak.

appwrite audit auditor baas cli devsecops leak mit-license nodejs open-source penetration-testing scanner security security-audit typescript vulnerability

Last synced: 25 Jun 2026

https://github.com/chaluvadis/safe-to-send

safe-to-send is a minimal VS Code extension to scan selected code (or full file) for sensitive data before copying for manual AI usage.

agent-skills agents ai clipboard security sensitive-data typescript utilities utility vscode-extension

Last synced: 25 Jun 2026

https://github.com/Perufitlife/appwrite-security-skill

Open-source Appwrite security auditor: detects 'any' role grants, document security misconfig, over-permissive collection permissions. Active probe confirms each leak.

appwrite audit auditor baas cli devsecops leak mit-license nodejs open-source penetration-testing scanner security security-audit typescript vulnerability

Last synced: 25 Jun 2026

https://github.com/perufitlife/dotenv-exposure-check

Zero-dep CLI that probes a live URL for accidentally-served secret artifacts (.env, .git/, .js.map source maps, .DS_Store, backups) and CONFIRMS each hit by fetching the bytes.

devsecops dotenv env exposure-scanner secret-scanning secrets-detection security security-audit security-tools sourcemap

Last synced: 25 Jun 2026

https://github.com/Perufitlife/ollama-security

Active-probe security auditor for Ollama: detects a publicly bound, unauthenticated API and PROVES model/compute leaks live via anonymous /api/tags, /api/ps, /api/generate and CORS probes. Zero deps, MIT.

ai-agents cors devsecops llm llm-security local-ai local-llm ollama security security-audit

Last synced: 25 Jun 2026

https://github.com/sulthonzh/envault

Zero-dep .env file encryption for teams — encrypt, decrypt, diff, merge secrets with a passphrase

aes decrypt dotenv encrypt env passphrase secrets security

Last synced: 25 Jun 2026

https://github.com/sulthonzh/mcp-audit

Security scanner for MCP (Model Context Protocol) servers

agent ai audit cli mcp scanner security vulnerability

Last synced: 25 Jun 2026

https://github.com/gpuslave/cyphering

Some security code implementation using Rust

rust security

Last synced: 20 Jul 2026

https://github.com/l1asis/vault-tar

AES-256-GCM file and directory encryption CLI with chunked streaming, configurable compression, and output splitting.

aes-256-gcm archiving cli compression cryptography directory-encryption encryption file-encryption pbkdf2 privacy python security

Last synced: 14 Feb 2026

https://github.com/davealdon/anti-csrf-csp

🔑🔒 A method for mitigating anti CSRF attacks on CSP derived api calls

api csrf csrf-prevention intersystems intersystems-cache intersystems-iris objectscript security

Last synced: 14 Feb 2026

https://github.com/florianreuth/pit

pit - the private information tracker

data java passwords security vault

Last synced: 28 Feb 2026

https://github.com/gabrielefalace/threat-flow

a condensed STRIDE and LINDDUN inspired threat modeling technique.

security threat-modeling

Last synced: 28 Feb 2026

https://github.com/dotnetextensions/oauth20.server.host

Hosted OAuth 2.0 Authorization Server for ASP.NET Core, featuring built-in OAuth 2.0 endpoints, Blazor-based Admin Panel and Personal Account UI, and support for various deployment options including Docker, Kubernetes, Helm, and Windows Service/IIS. Leverages core libraries from DotNetExtensions.OAuth20.

aspnetcore authentication authorization authorization-server blazor cross-platform docker dotnet dotnetcore dotnetframework helm iis kubernetes security windows-service

Last synced: 28 Feb 2026

https://github.com/joris-gallot/grantify

Lightweight framework-agnostic RBAC and permission management toolkit

access-control acl auth authorization permissions rbac roles security

Last synced: 15 Feb 2026

https://github.com/barzik/securitysample

My presentations and demo on Node.js Security

presentation security

Last synced: 14 Feb 2026

https://github.com/interactive-inc/open-mcp-guardrails

Policy-based guardrails proxy that protects MCP servers from PII leaks, secret exposure, and prompt injection

claude llm mcp npm security typescript

Last synced: 19 Feb 2026

https://github.com/guitargnarr/meridian

React dashboard for PhishGuard ML phishing detection. Real-time URL analysis with threat scoring visualization.

phishing-detection react security tailwindcss typescript

Last synced: 15 Feb 2026

https://github.com/mehmettopcu/oslo.policy.remote

Remote Policy Checker for Oslo Policy - A Python package that enables remote HTTP-based policy checking, allowing policy decisions to be made by a remote service. Works with goslo.policy.server for centralized policy enforcement in OpenStack services.

authorization microservices openstack oslo policy rbac rest-api security yaml-configuration

Last synced: 15 Feb 2026