{
  "count": 10,
  "kind": "all",
  "sorts": [
    "kind",
    "stars",
    "name"
  ],
  "facets": {},
  "facetCounts": {},
  "outputs": [
    "json",
    "xml",
    "csv",
    "sse",
    "events"
  ],
  "resources": [
    {
      "slug": "snyk",
      "name": "Snyk",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://snyk.io",
      "description": "SAST/SCA/secret scanning platform + MCP + CLI.",
      "access": "api",
      "pricing": "freemium",
      "github": {
        "repo": "snyk/cli",
        "stars": 5663,
        "starsAsOf": "2026-09-19"
      },
      "caps": [
        "sast",
        "sca",
        "deps",
        "mcp"
      ],
      "kinds": [
        "security-tool",
        "api-service"
      ],
      "facets": {
        "scanType": [
          "sast",
          "sca",
          "container",
          "iac",
          "secrets",
          "deps"
        ],
        "oss": "false",
        "topic": [
          "security",
          "sast",
          "deps"
        ],
        "host": [
          "generic"
        ],
        "caps": [
          "sast",
          "sca",
          "deps",
          "mcp"
        ]
      }
    },
    {
      "slug": "sonarqube",
      "name": "SonarQube",
      "kind": "security-tool",
      "tags": [
        "security",
        "sast"
      ],
      "links": [],
      "url": "https://www.sonarsource.com/products/sonarqube",
      "description": "Code quality + security analysis platform.",
      "access": "self-host",
      "pricing": "freemium",
      "caps": [
        "sast",
        "quality"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "false"
      }
    },
    {
      "slug": "codeql",
      "name": "CodeQL",
      "kind": "security-tool",
      "tags": [
        "security",
        "github"
      ],
      "links": [],
      "url": "https://codeql.github.com",
      "description": "GitHub's semantic code analysis.",
      "access": "api",
      "pricing": "free",
      "caps": [
        "sast"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "false"
      }
    },
    {
      "slug": "bandit",
      "name": "Bandit",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/PyCQA/bandit",
      "description": "Python security linter.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "PyCQA/bandit"
      },
      "caps": [
        "sast",
        "python"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "bearer",
      "name": "Bearer",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/Bearer/bearer",
      "description": "Privacy + security SAST.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "Bearer/bearer"
      },
      "caps": [
        "sast",
        "privacy"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast",
          "privacy"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "mobsf",
      "name": "MobSF",
      "kind": "security-tool",
      "tags": [
        "security",
        "mobile"
      ],
      "links": [],
      "url": "https://mobsf.github.io/Mobile-Security-Framework-MobSF",
      "description": "Mobile app security framework.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "MobSF/Mobile-Security-Framework-MobSF"
      },
      "caps": [
        "mobile",
        "sast",
        "dast"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "mobile",
          "sast",
          "dast"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "horusec",
      "name": "Horusec",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/ZupIT/horusec",
      "description": "SAST + secrets + deps orchestrator.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "ZupIT/horusec"
      },
      "caps": [
        "sast",
        "secrets",
        "deps"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast",
          "secrets"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "snyk-code",
      "name": "Snyk",
      "kind": "skill-source",
      "tags": [
        "security",
        "sast",
        "deps"
      ],
      "links": [],
      "url": "https://snyk.io",
      "description": "SAST/SCA/secret scanning + MCP + CLI.",
      "access": "api",
      "pricing": "freemium",
      "github": {
        "repo": "snyk/cli",
        "stars": 5663,
        "starsAsOf": "2026-09-19"
      },
      "kinds": [
        "security-tool",
        "skill-source"
      ],
      "facets": {
        "scanType": [
          "sast",
          "deps"
        ],
        "oss": "false",
        "topic": [
          "security",
          "sast",
          "deps"
        ],
        "host": [
          "generic"
        ]
      }
    },
    {
      "slug": "strix-find-vulns-skill",
      "name": "Find security vulnerabilities (Strix)",
      "kind": "skill-source",
      "tags": [
        "security",
        "sast",
        "t3rnel"
      ],
      "links": [],
      "url": "https://github.com/t3ratech/t3rnel",
      "description": "White-box security review + live exploit proofs.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "t3ratech/t3rnel"
      },
      "kinds": [
        "skill-source"
      ],
      "facets": {
        "topic": [
          "security",
          "sast"
        ],
        "host": [
          "t3rnel"
        ],
        "oss": [
          "true"
        ]
      }
    },
    {
      "slug": "semgrep",
      "name": "Semgrep",
      "kind": "skill-source",
      "tags": [
        "security",
        "sast"
      ],
      "links": [],
      "url": "https://semgrep.dev",
      "description": "Static analysis rule engine.",
      "access": "oss",
      "pricing": "freemium",
      "github": {
        "repo": "semgrep/semgrep"
      },
      "kinds": [
        "security-tool",
        "skill-source"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "true",
        "topic": [
          "security",
          "sast"
        ],
        "host": [
          "generic"
        ]
      }
    }
  ]
}