We check every product on this page once a day and record whether it still answers.
An open-source runtime for building and running production AI agent systems, for developers who don't want to hand-roll retrieval, memory, and execution logic.
Open sourceSelf-hosted
What to know▼
How it works
Handles retrieval, memory, model routing, and verification instead of hardcoded pipelines
What's different
Self-hostable, open-source, with governed execution including planning, verification, and replay
Best for
Developers building production AI systems in Python or Go
We check every product on this page once a day and record whether it still answers.
Open-source malware scanner and runtime guard for AI agents
FreeWorks offlineOpen source
What to know▼
How it works
Vets AI agent skills and MCP servers for malicious behavior before install, scans what's already installed, and blocks hijack attempts at runtime, using 768 open ATR rules.
What's different
Scanned 96,096 published skills and found 751 malicious; rules already merged into Microsoft, Cisco, MISP, and OWASP tooling.
We check every product on this page once a day and record whether it still answers.
A free, open-source Chrome DevTools extension for testing APIs — capture, inspect, edit, and replay HTTP requests without an external proxy, plus a quick header and secrets audit.
FreeOpen source
What to know▼
How it works
A Chrome DevTools extension that captures, inspects, edits, and replays HTTP/HTTPS requests without an external proxy, plus a Quick Security Check that audits headers and flags secrets or PII.
What's different
Works without needing to route traffic through an external proxy, unlike typical API testing setups.
Pricing
Free and open-source.
Best for
Developers testing API security directly inside Chrome DevTools.
We check every product on this page once a day and record whether it still answers.
Local firewall binary that sits between AI agents and the network to block secret leaks, prompt injection, SSRF, and MCP tool poisoning, for developers running autonomous agents, producing a signed offline-verifiable receipt instead of blind trust.
No sign-upWorks offlineOpen source
What to know▼
How it works
A single Go binary scans every outbound request from an agent and writes a signed receipt you verify offline against a published key when it blocks something.
Pricing
Apache 2.0, install via brew.
Best for
Developers whose AI agents have shell access, secrets, and an open line to the internet.
We check every product on this page once a day and record whether it still answers.
An open-source local tool for planning and executing encrypted-file key rotation with AI-assisted threat interpretation and policy controls.
Open source
What to know▼
How it works
An open-source local tool that turns recipient changes into reviewable key-rotation plans, with AI interpreting threat signals while deterministic policy controls approval and execution.
What's different
Keys, plaintext, and ciphertext never pass through the model; includes a bundled post-quantum sample vault run with Docker.
We check every product on this page once a day and record whether it still answers.
Local-first Terraform scanner that audits cost, security and reliability in one pass with no upload, MIT licensed.
No sign-upWorks offlineData stays with you
What to know▼
How it works
Scans Terraform locally for security, cost, reliability, and governance issues in one pass, and writes the patch when a cost fix and a security risk hit the same resource.
We check every product on this page once a day and record whether it still answers.
A free, open-source, MIT-licensed penetration-testing agent bundling 90+ recon tools (nmap, nuclei, sqlmap and more) into a three-agent pipeline — for security engineers running assessments from the command line.
FreeOpen source
What to know▼
How it works
A reconnaissance agent that runs from inside the environment being tested (desktop, mobile, terminal or headless), bundling 90+ pentest tools like nmap, nuclei, sqlmap and aircrack-ng, plus native port scanning, device enumeration, WiFi discovery and packet capture. A three-agent pipeline (red team, validator, report) turns recon into verified findings.
What's different
Single Rust/Dioxus codebase across desktop, mobile, terminal and headless environments, and is MIT licensed so it can be inspected and extended.
Pricing
Free and open-source, MIT licensed.
Best for
Security engineers running penetration tests who want a bundled, extensible recon and reporting agent.
We check every product on this page once a day and record whether it still answers.
A continuous security scanner that re-checks targets on a schedule and alerts only on new vulnerability findings.
FreeOpen source
What to know▼
How it works
Schedules recurring security scans (daily/weekly/monthly) with 50+ detectors across recon, web, API, and mobile, alerting via email/Discord/Slack only on new findings versus the previous run; tracks attack surface over time and ships a CLI plus GitHub Action to fail CI builds on new criticals.
What's different
Alerts only on new findings instead of re-reporting everything on each run, and remembers triage decisions across re-scans.
We check every product on this page once a day and record whether it still answers.
An open-source reference guide covering AI and ML security practices, including LLM, RAG, agent, and MLOps supply-chain controls, for developers and ML engineers.
Open source
What to know▼
How it works
Documents practical MLSecOps guidance across AI security, ML security, LLM/RAG/agent security, and ML supply-chain controls.
Best for
Developers and ML engineers securing AI/ML systems.
We check every product on this page once a day and record whether it still answers.
A free, open-source macOS app for editing your $PATH, aliases and environment variables through a drag-and-drop UI instead of hand-editing shell config files.
Open source
What to know▼
How it works
A macOS app with a drag-and-drop dashboard for editing your $PATH, toggling shell aliases, and managing environment variables, with sensitive keys secured behind Touch ID.
What's different
Replaces hand-editing shell config files with a visual UI, and is under 1.4MB, open source, built in SwiftUI.
Pricing
Open source.
Best for
Developers on macOS who are tired of manually editing dotfiles to manage PATH, aliases and env variables.
We check every product on this page once a day and record whether it still answers.
A drop-in CAPTCHA replacement — a short reaction game easy for humans and hard for bots — that collects no visitor IP, fingerprint or tracking data, with an open-source widget.
Open sourceNo tracking
What to know▼
How it works
Replaces the usual CAPTCHA puzzle with a short reaction-based game; every round is re-checked on the server, so it's easy for humans but hard for bots and AI solvers.
What's different
Collects no IP, fingerprint, or tracking data about visitors, and the widget and games are open source for developers to inspect and restyle.
Best for
Developers who want a privacy-respecting, open-source CAPTCHA alternative for their site.