Finding leaked credentials, testing your own applications, and blocking the traffic that should not reach them.
These supplement a real audit; none of them satisfies a customer who has asked for one.
Moving fastest this week: shannon (+1.0k), pentagi (+752), SkillSpector (+659).
Mature enough to put in production this quarter.
Secrets scanner for Git repos
Instead of: Manual secret auditing
Finds leaked credentials in code
Instead of: Manual credential audits
Daemon to ban hosts with multiple auth errors
Instead of: Manual IP blocking
Cloud security auditing tool
Instead of: Manual security audits or paid tools
Security auditing tool for Linux and UNIX
Instead of: Manual security audits
Loads env vars from .env files
Instead of: Manual env var setup
Worth a timeboxed spike before you bet on it.
AI security scanner for agent skills
Instead of: Manual security reviews of AI code
An autonomous agent that tests your own web application for security holes and writes up what it finds.
Instead of: A four-figure penetration-testing engagement, or shipping untested.
Open source security platform for endpoint and cloud protection
Instead of: Splunk or manual log analysis
OSINT tool for website analysis
Instead of: manual website reconnaissance
Windows user mode debugger
Instead of: paid debuggers like IDA Pro
Fast port scanner written in Rust
Instead of: Nmap or manual port checks
Intranet vulnerability scanner
Instead of: Manual vulnerability checks
Real software; just not where a small team's next hundred hours should go.
AI-powered penetration testing tool
Instead of: manual pen testing or paid tools
Open-source secrets and access management
Instead of: Manual secrets management or paid tools like Hashicorp Vault
Tell us what you sell in one sentence and we will hand you three specific moves — priced per month, with the arithmetic shown. Free, no signup.
Give me three moves