Security — independent software & tools
-
keel
A local-first, governed agent harness: high autonomy inside structurally-enforced boundaries (Autopilot, not YOLO).
-
forgeterm
Monitor AI coding agents in real-time to block unauthorized file access, network connections, and dangerous commands while enforcing system resource limits.
-
aishield
🛡️ Agent-native AI tool security scanner. Scan MCP/Skill/GPT/Prompt for security risks. 4-dimensional scoring. Certified badges. Guardrail MCP for auto-protection.
-
webscan
Automated CLI security auditor for web configuration vulnerabilities.
-
sober-coding
Analyze AI-generated code to find technical debt and get actionable fixes.
-
targate
AI-assisted pre-install security gate for npm packages — analyze, decide, and gate a dependency before it runs.
-
mcp-sentinel
🛡️ Secure MCP server that lets AI cloud services (Claude, ChatGPT, Gemini, Cursor) remotely control Linux servers. HTTP/SSE transport · API key + JWT auth · IP whitelist · 20 tools · role-based access · audit logs.
-
headscale-install
Install and configure a Headscale server on Linux with automated setup, user management, and verified binaries
-
repopilot
Local-first CLI for reviewing Git changes, security boundaries, and blast radius before merge.
-
snitch
Single static-binary recon orchestrator in Go: chains subfinder, httpx, nmap, nuclei, ffuf, katana + injection testing (dalfox/crlfuzz/sqlmap), with dedup, diff-based webhook alerts, an interactive TUI and JSON/CSV/SARIF export.
-
npm-safe
本地优先的 npm 包供应链安全扫描引擎:静态与 LLM 分析、CLI、桌面 GUI、CI 集成。
-
gurgl
Local-first egress hygiene for MCP servers: capture, diff, and allowlist what your AI-agent tools contact on the network.
-
ssh-mcp-pro
TypeScript MCP server for controlled SSH operations, remote host workflows, command execution guardrails, and infrastructure automation.
-
svelte-vitals
A static code-health checker for SvelteKit — SEO, Performance, Correctness, Security, and Architecture, from source. Not a runtime Web Vitals reporter.
-
sysPass
sysPass - Systems Password Manager (fork for maintenance & upgrades)
-
mcp-krb-server
Kerberos/SPNEGO single sign-on for MCP servers in FreeIPA environments. Provisioning framework for Windows (via WSL), Linux and macOS development environments.
-
triagekit
Backend-free repo triage in one self-contained HTML file — GitHub Dependabot alerts, code scanning, PRs & issues, scored and tiered. No server, no CDN; your token stays in the browser.
-
purrsh3ll
AI-powered terminal environment for penetration testers
-
remnant
Deterministic npm artifact admission for local and CI supply-chain checks.
-
contextduty
Policy-driven context firewall for AI workflows — redact secrets and PII before prompts leave your machine
-
pinprick
Pin your GitHub Actions. Prick holes in their supply chain security.
-
herdr-guard
Cross-agent command policy for Herdr: audit, alert, and interrupt dangerous shell commands
-
VibeCoder
Unattended GitHub issue-to-PR worker running Claude Code inside a strict containment boundary
-
tenant-isolation-postgres
Multi-tenant isolation in PostgreSQL: RLS row scope + a privileged-column trigger that closes the gap RLS cannot express + security-definer metering. 15 integration tests execute the attacks and assert they fail.
-
numan
The missing package management layer for Nushell. Brings verified registry support, lockfiles, and managed autoloading to plugins, modules, scripts, and completions.
-
GrantTrace
Scenario-bound GitHub App REST permission contracts.
-
trustabl-action
GitHub Action that runs trustabl — static reliability/safety analyzer for AI agent SDKs (Claude, OpenAI, Google ADK, MCP). Gates CI on risk + severity.
-
trusca
Self-hosted, open-source SCA portal — vulnerability (CVE), license compliance, and SBOM management in one UI. Black Duck/Snyk-class capabilities, Apache-2.0.
-
aicheck-scan
Fail the build if your PR ships an exposed self-hosted AI service. Live-probes Ollama, n8n, vLLM, Langfuse, Open WebUI and 12 more — graded A–F report, fix-card links, SARIF code scanning.
-
hideout
Run AI agents and untrusted CLIs in a local VM without losing host-native workflows.
-
mcp-security-lab
Evidence-first security checks for Model Context Protocol (MCP) servers — a Claude for OSS Incubator project.
-
meshmcp
The identity-native control plane for agent↔tool (MCP) traffic. Every MCP server runs on a private WireGuard mesh — zero open ports — behind an agent firewall: tamper-evident signed audit, policy learned from behavior, identity-gated secrets, and audited cross-org federation. One static Go binary.
-
tiyi
Single-binary WAF platform with Caddy, Coraza, OWASP CRS, CLI, Web UI, SQLite state, and signed releases. The WAF that grows with you.
-
opencode-gitlab-auth
GitLab OAuth authentication plugin for OpenCode
-
Aer - Fork of Anemo
Private storage utility for android with support for external storage media
-
ANONguard
ANONguard anonymises the Internet connection
-
Motion-UI
A web interface to manage your own NVR with motion.
-
Password Store
Manage your passwords
-
MemoryGuardian
Take Control of Your Clipboard
-
Better Internet Tiles
Bring back Wi-Fi and mobile data tiles on Android 12 or higher
-
Port Knocker
Port knocker client; supports one time sequences
-
Guerrilla Mail
Quickly receive anonymous and temporary mails.
-
PilferShush Jammer
Block unwanted use of onboard microphone
-
Port Authority
Port scanner
-
AdGuard Content Blocker
Ad blocker app to block ads in Yandex Browser and Samsung Internet browser only
-
Simple Text Crypt
Encrypts plain text using AES256
-
Ruam Mij
Suspicious app scanner with privacy respects
-
Wassword - Wonderful Password Generator
Create unbreakable passwords in one tap
-
KryptEY
Keyboard for secure E2EE communication through signal protocol in any messenger
-
KeePassDroid
KeePass-compatible password safe
-
Diceware Password Generator
Generate diceware passwords
-
SafeDot
alerts you when a third-party application uses your device camera or microphone
-
Vault
Simple, secure and fast password manager compatible with KeePass
-
Aegis Authenticator
Free, secure and open source 2FA app to manage tokens for your online services
-
SharedHaven
Bitcoin wallet with secure multisig features
-
Sidestep
Intercept URLs, remove tracking, and redirect to privacy-friendly frontends.
-
URnetwork
Goodbye VPN!
-
Rivia
Rivia is the ultimate encryption tool
-
Saracroche
Block unwanted spam calls automatically and protect your privacy
-
Pushie
Provides temporary, secure, password sharing