An awesome list of OSS developer-first security tools
-
Updated
May 15, 2025
An awesome list of OSS developer-first security tools
An ongoing & curated collection of awesome software practices and remediation, libraries and frameworks,payloads and techniques, best guidelines and technical resources about Application Security
Application scanning component of OWASP PurpleTeam
Fleet AI Security Posture Management (AI-SPM): client agents on each developer machine score their AI coding agents' guard surfaces (Claude Code, Cursor, Codex, Gemini CLI — permissions, hooks, sandboxes, mcp.json) and ship hash-anchored events to a central server + your SIEM. Fleet-wide posture; measures, doesn't block. Rust.
TLS scanning component of OWASP PurpleTeam
NEXUS REDFOX — Local-first code intelligence and security analysis platform for developers and security researchers.
Infrastructure as Code for SUTs
Server scanning component of OWASP PurpleTeam
Stage Two containers of OWASP PurpleTeam
AWS Lambda functions of OWASP PurpleTeam
Post-compromise forensic tool for developer workstations
Security scanner for VSIX, MCP, AI IDEs, and developer workflow attack paths.
How to identify, analyze, and report targeted phishing campaigns on GitHub — with real-world case studies and a step-by-step takedown workflow.
Instructions and materials to run the HIPSTER workshop
Zero-trust API firewall and security integrity layer for autonomous AI agents & Model Context Protocol (MCP) tool execution. Secure, TOCTOU-proof, fail-closed.
AI-powered vulnerability reporting platform that automates pentest report generation from raw findings into professional, client-ready deliverables.
Claude Code skill that hardens package manager configs against supply chain attacks. Run /harden once, it detects what you have and secures it.
Free MCP + AI agent trust preflight: 20 practical checks, safe examples, VS Code tooling, drift review and authority analysis.
Official ECZ-ID Agent Trust product and documentation hub. Local-first agent inventory, authority and change inspection for VS Code.
Endpoint security for the AI developer — monitor what AI coding agents actually do on your machine.
Add a description, image, and links to the developer-security topic page so that developers can more easily learn about it.
To associate your repository with the developer-security topic, visit your repo's landing page and select "manage topics."