Topic

Tools for finding security holes in code · Works offline

15

match your filters

14

answered today

0

arrived this week

0

stopped answering

Watching this group for 26 days, checked once a day · how we check

HeimWall

LiveWatched 15d

Local macOS scanner that blocks secrets and PII from leaking into AI coding-tool prompts, for engineers who don't want to rely on cloud DLP.

FreeWorks offline
What to know
How it works
A macOS app that scans prompts in real time before they reach AI coding tools like Cursor, Claude Code, and Copilot, flagging leaked API keys, credentials, and PII using 47 local detection rules in under 50ms.
What's different
Detection happens on-device before data leaves the machine, and uses soft notifications instead of hard blocks so it doesn't interrupt the coding flow.
Pricing
Free 15MB macOS application for engineers; an early-access dashboard is offered separately for organizations.
Best for
Engineers using AI coding assistants who want to avoid pasting live secrets into prompts.
Details →

Panguard.AI

LiveWatched 14d

Open-source malware scanner and runtime guard for AI agents

FreeWorks offlineOpen source
What to know
How it works
Vets AI agent skills and MCP servers for malicious behavior before install, scans what's already installed, and blocks hijack attempts at runtime, using 768 open ATR rules.
What's different
Scanned 96,096 published skills and found 751 malicious; rules already merged into Microsoft, Cisco, MISP, and OWASP tooling.
Pricing
Free, MIT licensed, fully on-device.
Details →

Synapsor Runner

LiveWatched 11d

A tool that replaces raw SQL access for AI database agents with human-approved, scoped business actions instead of full read/write authority.

No sign-upWorks offline
What to know
How it works
tenant-scoped semantic tools like billing.propose_late_fee_waiver; writes need human approval outside the model's reach
What's different
includes a CLI audit command to score an existing MCP setup's risk
Pricing
local-first, open source (Apache-2.0), no account needed
Details →

Pipelock

LiveWatched 13d

Local firewall binary that sits between AI agents and the network to block secret leaks, prompt injection, SSRF, and MCP tool poisoning, for developers running autonomous agents, producing a signed offline-verifiable receipt instead of blind trust.

No sign-upWorks offlineOpen source
What to know
How it works
A single Go binary scans every outbound request from an agent and writes a signed receipt you verify offline against a published key when it blocks something.
Pricing
Apache 2.0, install via brew.
Best for
Developers whose AI agents have shell access, secrets, and an open line to the internet.
Details →

Cairn

LiveWatched 9d

Local-first Terraform scanner that audits cost, security and reliability in one pass with no upload, MIT licensed.

No sign-upWorks offlineData stays with you
What to know
How it works
Scans Terraform locally for security, cost, reliability, and governance issues in one pass, and writes the patch when a cost fix and a security risk hit the same resource.
What's different
No account, no upload, zero network calls.
Pricing
Free, MIT licensed.
Details →

Depheal

LiveWatched 13d

An offline scanner that checks Python projects for known CVE vulnerabilities using local AST analysis, instead of a cloud-based dependency scanner.

Works offlineOpen source
What to know
How it works
Static AST analysis run entirely locally, with no internet connection or external dependencies required.
Pricing
Open source, published on PyPI.
Best for
Developers who want fast vulnerability scanning without sending code to a cloud service.
Details →

Baseplate

LiveWatched 15d

Runs AI agents that playtest a Roblox game, catch bugs, and patch the source code locally.

Watch out · Runs locally on Windows and macOS.

Works offline
What to know
How it works
AI agents playtest a Roblox game inside the workflow, catch runtime errors, write fixes in Luau source, and verify them live in Studio.
Pricing
Free plan includes Exploit Guard, an audit of every RemoteEvent with server-side fix suggestions; no card required.
Watch out
Runs locally on Windows and macOS.
Details →

A browser extension that scans pages you visit for exposed API keys and secrets (OpenAI, AWS, Stripe, GitHub, Google) entirely locally. Built for developers and security engineers guarding against credential leaks.

Works offlineData stays with you
What to know
How it works
A browser extension that scans pages you visit for exposed API keys and secrets from providers like OpenAI, AWS, Stripe, GitHub, and Google, checking the DOM, scripts, and network responses.
What's different
Scanning happens 100% locally — nothing leaves your browser.
Best for
Developers and security engineers who want to catch accidentally exposed credentials while browsing.
Details →

MeshaSec

LiveWatched 2d
Works offline
Details →

Sunglasses

LiveWatched 5d
No sign-upWorks offlineOpen source
Details →
No sign-upWorks offlineNo subscription
Details →

Rebrief

LiveWatched 4d
FreeWorks offlineOpen source
Details →

Fidacy

LiveWatched 2d
FreeWorks offline
Details →

Soterios

LiveWatched 2d
Works offlineOpen source
Details →

A browser-based static code security scanner for Python and JavaScript that runs entirely offline with no install, aimed at developers checking for vulnerabilities missed by tools like Semgrep.

Nothing to installWorks offline
What to know
How it works
Paste Python or JavaScript code into the browser and it runs a static security analysis (SAST) entirely offline, with no install required.
What's different
Runs 100% offline with no install, and is positioned to catch vulnerabilities that tools like Semgrep and CodeQL miss.
Best for
Developers who want a quick, local vulnerability check on a code snippet without setting up a full scanning pipeline.
Details →