An awesome list of OSS developer-first security tools
-
Updated
May 15, 2025
An awesome list of OSS developer-first security tools
An ongoing & curated collection of awesome software practices and remediation, libraries and frameworks,payloads and techniques, best guidelines and technical resources about Application Security
Application scanning component of OWASP PurpleTeam
NEXUS REDFOX — Local-first code intelligence and security analysis platform for developers and security researchers.
Fleet AI Security Posture Management (AI-SPM): client agents on each developer machine score their AI coding agents' guard surfaces (Claude Code, Cursor, Codex, Gemini CLI — permissions, hooks, sandboxes, mcp.json) and ship hash-anchored events to a central server + your SIEM. Fleet-wide posture; measures, doesn't block. Rust.
TLS scanning component of OWASP PurpleTeam
Infrastructure as Code for SUTs
Server scanning component of OWASP PurpleTeam
Stage Two containers of OWASP PurpleTeam
AWS Lambda functions of OWASP PurpleTeam
How to identify, analyze, and report targeted phishing campaigns on GitHub — with real-world case studies and a step-by-step takedown workflow.
Security scanner for VSIX, MCP, AI IDEs, and developer workflow attack paths.
Post-compromise forensic tool for developer workstations
Instructions and materials to run the HIPSTER workshop
Zero-trust API firewall and security integrity layer for autonomous AI agents & Model Context Protocol (MCP) tool execution. Secure, TOCTOU-proof, fail-closed.
Claude Code skill that hardens package manager configs against supply chain attacks. Run /harden once, it detects what you have and secures it.
AI-powered vulnerability reporting platform that automates pentest report generation from raw findings into professional, client-ready deliverables.
Practical MCP readiness, security and stateless-migration resources for teams moving MCP servers toward enterprise deployment.
Official ECZ-ID Agent Trust product and documentation hub. Local-first agent inventory, authority and change inspection for VS Code.
Practical examples for organisational machine identity, parent-child identity relationships and resolver-first evidence using ECZ-ID Business Passports.
Add a description, image, and links to the developer-security topic page so that developers can more easily learn about it.
To associate your repository with the developer-security topic, visit your repo's landing page and select "manage topics."