An awesome list of OSS developer-first security tools
-
Updated
May 15, 2025
An awesome list of OSS developer-first security tools
An ongoing & curated collection of awesome software practices and remediation, libraries and frameworks,payloads and techniques, best guidelines and technical resources about Application Security
Application scanning component of OWASP PurpleTeam
Fleet AI Security Posture Management (AI-SPM): client agents on each developer machine score their AI coding agents' guard surfaces (Claude Code, Cursor, Codex, Gemini CLI — permissions, hooks, sandboxes, mcp.json) and ship hash-anchored events to a central server + your SIEM. Fleet-wide posture; measures, doesn't block. Rust.
NEXUS REDFOX — Local-first code intelligence and security analysis platform for developers and security researchers.
TLS scanning component of OWASP PurpleTeam
Infrastructure as Code for SUTs
Server scanning component of OWASP PurpleTeam
Stage Two containers of OWASP PurpleTeam
AWS Lambda functions of OWASP PurpleTeam
How to identify, analyze, and report targeted phishing campaigns on GitHub — with real-world case studies and a step-by-step takedown workflow.
Post-compromise forensic tool for developer workstations
Security scanner for VSIX, MCP, AI IDEs, and developer workflow attack paths.
Instructions and materials to run the HIPSTER workshop
Zero-trust API firewall and security integrity layer for autonomous AI agents & Model Context Protocol (MCP) tool execution. Secure, TOCTOU-proof, fail-closed.
AI-powered vulnerability reporting platform that automates pentest report generation from raw findings into professional, client-ready deliverables.
Claude Code skill that hardens package manager configs against supply chain attacks. Run /harden once, it detects what you have and secures it.
Free MCP + AI agent trust preflight: 20 practical checks, safe examples, VS Code tooling, drift review and authority analysis.
Practical MCP readiness, security and stateless-migration resources for teams moving MCP servers toward enterprise deployment.
Free AI agent authority, permissions and reachability resources for understanding what agents can access before they act.
Add a description, image, and links to the developer-security topic page so that developers can more easily learn about it.
To associate your repository with the developer-security topic, visit your repo's landing page and select "manage topics."