Skip to content

Tools

Developer tools directory 51 tools

Submit tool
Category
Health
#security

51 tools

UPinar/contrastapi Healthy open source

Security intelligence API with 31 MCP tools for CVE/EPSS/KEV lookup, domain recon (DNS/WHOIS/SSL/subdomains/CT logs), IOC/threat intel, OSINT (email/phone/username), and code security scanning (secrets, injection). Free 100 req/hr.

infisical Healthy open source

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Prowler Healthy open source

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

pentest-ai Healthy open source

Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.

microsandbox Healthy open source

secure, local, cross-platform and programmable sandboxes for AI agents

msaad00/agent-bom Healthy open source

AI supply chain security scanner with 18 MCP tools. Auto-discovers 20 MCP clients, scans dependencies for CVEs (OSV/NVD/EPSS/CISA KEV), maps blast radius from vulnerabilities to exposed credentials and tools, runs CIS benchmarks, generates CycloneDX/SPDX SBOMs, and enforces compliance across OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and EU AI Act.

Fleet device management Healthy open source

Open device management

authentik Healthy open source

The authentication glue you need.

MyIP Healthy open source

All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.

OpenZiti Healthy open source

Fully-featured, zero trust, full mesh overlay network. Includes a 2FA support out of the box, clients for all major desktop/mobile OS'es.

Pompelmi Healthy open source

Open-source file upload security for Node.js. Scan files before storage to detect malware, MIME spoofing, and risky archives.

Cosmos-Server Healthy open source

☁ The Most Secure and Easy Selfhosted Home Server. Take control of your data and privacy without sacrificing security and stability (Authentication, anti-DDOS, anti-bot)

teleport Healthy open source

The easiest, and most secure way to access and protect all of your infrastructure.

beelzebub Healthy open source

Honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks.

PasswordPusher Healthy open source

Securely share sensitive information with automatic expiration & deletion after a set number of views or duration. Track who, what and when with full audit logs.

trufflehog Healthy open source

Find, verify, and analyze leaked credentials

voidauth Healthy open source

Single Sign-On for Your Self-Hosted Universe

gebalamariusz/cloud-audit Healthy open source

Open-source AWS security scanner with attack chain detection, breach cost estimation, and copy-paste remediation (CLI + Terraform). 47 checks, 16 attack chain rules. First free standalone AWS security MCP server.

NGINX Healthy open source

HTTP and reverse proxy server, mail proxy server, and generic TCP/UDP proxy server.

kanidm Healthy open source

Kanidm: A simple, secure, and fast identity management platform

VAST Healthy open source

Open source security data pipeline engine for structured event data, supporting high-volume telemetry ingestion, compaction, and retrieval; purpose-built for security content execution, guided threat hunting, and large-scale investigation.

Cardea Healthy open source

SSH bastion server with access control, session recording, and optional TPM-backed key protection. `EUPL-1.2` `Go/Docker`

GlobaLeaks Healthy open source

Whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

AI-Infra-Guard by Tencent Zhuque Lab Healthy open source

A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

Splunk Security Content Healthy open source

Splunk Security Content

bytebase Healthy open source

World's most advanced database DevSecOps solution for Developer, Security, DBA and Platform Engineering teams. The GitHub/GitLab for database DevSecOps.

OxiCloud Healthy open source

☁ Ultra-fast, secure & lightweight self-hosted cloud storage — your files, photos, calendars & contacts, all in one place. Built in Rust.

goklab/guardvibe Healthy open source

Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.

Radare2 Healthy open source

UNIX-like reverse engineering framework and command-line toolset

Firezone Healthy open source

Enterprise-ready zero-trust access platform built on WireGuard®.

iris-eval/mcp-server Healthy open source

MCP-native agent evaluation and observability server with trace logging, output quality evaluation, cost tracking, 12 built-in eval rules, real-time dashboard, and PII detection.

matomo Healthy open source

Empowering People Ethically — Matomo is hiring! Join us → https://matomo.org/jobs Matomo is the leading open-source alternative to Google Analytics, giving you complete control and built-in privacy. Easily collect, visualise, and analyse data from websites & apps. Star us on GitHub ⭐ – Pull Requests welcome!

freema/openclaw-mcp Healthy open source

MCP server for OpenClaw AI assistant integration. Enables Claude to delegate tasks to OpenClaw agents with sync/async tools, OAuth 2.1 auth, and SSE transport for Claude.ai.

is-website-vulnerable Healthy open source

finds publicly known security vulnerabilities in a website's frontend JavaScript libraries

Stratus Red Team | DataDog Healthy open source

cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Zeek Healthy open source

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

mitmproxy Healthy open source

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

DockFlare Healthy open source

DockFlare: Automate Cloudflare Tunnels with Docker Labels

PrivateCaptcha Healthy open source

Independent, privacy-first, self-hostable PoW CAPTCHA service made in EU

openbao Healthy open source

OpenBao is a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys.

Arkime Healthy open source

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

passbolt_api Healthy open source

Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!

getaegis/aegis Healthy open source

Credential isolation proxy for AI agents. Injects secrets at the network boundary with domain restrictions, agent authentication, and audit logging. No SDK required — works as a transparent HTTP proxy or MCP server.

I4cTime/quantum_ring Healthy open source

Quantum-inspired keyring for AI coding agents. Secure secrets with superposition, entanglement, tunneling, and teleportation.

ajitpratap0/GoSQLX Healthy open source

7 SQL tools (validate, format, parse, lint, security scan, metadata extraction, full analysis) over Streamable HTTP. Public remote server at mcp.gosqlx.dev - no install needed. 1.25M+ ops/sec, 6 SQL dialects.

Sigma Healthy open source

Main Sigma Rule Repository

DigiCatalyst-Systems/dep-diff-mcp Healthy open source

Translates a lockfile diff (npm, PyPI) into a human-readable upgrade plan. Point it at a Dependabot PR and get back semver classification, breaking changes from GitHub release notes, CVEs fixed in range, migration links, and a per-package recommendation. Bulk tool ranks up to 50 changes by risk (security > caution > review > likely-safe > safe)

Bareos Healthy open source

Bareos is a cross-network Open Source backup solution (licensed under AGPLv3) which preserves, archives, and recovers data from all major operating systems.

jnMetaCode/shellward Healthy open source

AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.

wazuh Healthy open source

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

Beta — feedback welcome: [email protected]