{
  "count": 20,
  "kind": "security-tool",
  "sorts": [
    "stars",
    "name"
  ],
  "facets": {
    "scanType": [
      "sast",
      "sca",
      "dast",
      "secrets",
      "container",
      "iac",
      "mobile",
      "llm-sec",
      "pentest",
      "deps"
    ],
    "oss": [
      "true"
    ]
  },
  "facetCounts": {
    "scanType": {
      "classified": 20,
      "total": 20,
      "values": {
        "sast": 9,
        "sca": 6,
        "dast": 4,
        "secrets": 4,
        "container": 3,
        "iac": 3,
        "mobile": 1,
        "llm-sec": 1,
        "pentest": 2,
        "deps": 7
      }
    },
    "oss": {
      "classified": 20,
      "total": 20,
      "values": {
        "true": 16
      }
    }
  },
  "outputs": [
    "json",
    "xml",
    "csv",
    "sse",
    "events"
  ],
  "resources": [
    {
      "slug": "snyk-code",
      "name": "Snyk",
      "kind": "skill-source",
      "tags": [
        "security",
        "sast",
        "deps"
      ],
      "links": [],
      "url": "https://snyk.io",
      "description": "SAST/SCA/secret scanning + MCP + CLI.",
      "access": "api",
      "pricing": "freemium",
      "github": {
        "repo": "snyk/cli",
        "stars": 5663,
        "starsAsOf": "2026-09-19"
      },
      "kinds": [
        "security-tool",
        "skill-source"
      ],
      "facets": {
        "scanType": [
          "sast",
          "deps"
        ],
        "oss": "false",
        "topic": [
          "security",
          "sast",
          "deps"
        ],
        "host": [
          "generic"
        ]
      }
    },
    {
      "slug": "snyk",
      "name": "Snyk",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://snyk.io",
      "description": "SAST/SCA/secret scanning platform + MCP + CLI.",
      "access": "api",
      "pricing": "freemium",
      "github": {
        "repo": "snyk/cli",
        "stars": 5663,
        "starsAsOf": "2026-09-19"
      },
      "caps": [
        "sast",
        "sca",
        "deps",
        "mcp"
      ],
      "kinds": [
        "security-tool",
        "api-service"
      ],
      "facets": {
        "scanType": [
          "sast",
          "sca",
          "container",
          "iac",
          "secrets",
          "deps"
        ],
        "oss": "false",
        "topic": [
          "security",
          "sast",
          "deps"
        ],
        "host": [
          "generic"
        ],
        "caps": [
          "sast",
          "sca",
          "deps",
          "mcp"
        ]
      }
    },
    {
      "slug": "bandit",
      "name": "Bandit",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/PyCQA/bandit",
      "description": "Python security linter.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "PyCQA/bandit"
      },
      "caps": [
        "sast",
        "python"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "bearer",
      "name": "Bearer",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/Bearer/bearer",
      "description": "Privacy + security SAST.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "Bearer/bearer"
      },
      "caps": [
        "sast",
        "privacy"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast",
          "privacy"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "cargo-audit",
      "name": "cargo audit",
      "kind": "security-tool",
      "tags": [
        "security",
        "rust"
      ],
      "links": [],
      "url": "https://github.com/rustsec/rustsec",
      "description": "RustSec advisory scanner.",
      "access": "cli",
      "pricing": "free",
      "github": {
        "repo": "rustsec/rustsec"
      },
      "caps": [
        "deps",
        "sca",
        "rust"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "deps",
          "sca"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "checkov",
      "name": "Checkov",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://www.checkov.io",
      "description": "IaC security scanning.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "bridgecrewio/checkov"
      },
      "caps": [
        "iac",
        "terraform"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "iac"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "codeql",
      "name": "CodeQL",
      "kind": "security-tool",
      "tags": [
        "security",
        "github"
      ],
      "links": [],
      "url": "https://codeql.github.com",
      "description": "GitHub's semantic code analysis.",
      "access": "api",
      "pricing": "free",
      "caps": [
        "sast"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "false"
      }
    },
    {
      "slug": "gitleaks",
      "name": "Gitleaks",
      "kind": "skill-source",
      "tags": [
        "security",
        "secrets"
      ],
      "links": [],
      "url": "https://github.com/gitleaks/gitleaks",
      "description": "Secret scanning for repos.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "gitleaks/gitleaks"
      },
      "kinds": [
        "security-tool",
        "skill-source"
      ],
      "facets": {
        "scanType": [
          "secrets"
        ],
        "oss": "true",
        "topic": [
          "security",
          "secrets"
        ],
        "host": [
          "generic"
        ]
      }
    },
    {
      "slug": "grype",
      "name": "Grype",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/anchore/grype",
      "description": "Vuln scanner for images + filesystems.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "anchore/grype"
      },
      "caps": [
        "sca",
        "deps",
        "container"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sca",
          "deps",
          "container"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "horusec",
      "name": "Horusec",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/ZupIT/horusec",
      "description": "SAST + secrets + deps orchestrator.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "ZupIT/horusec"
      },
      "caps": [
        "sast",
        "secrets",
        "deps"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast",
          "secrets"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "mobsf",
      "name": "MobSF",
      "kind": "security-tool",
      "tags": [
        "security",
        "mobile"
      ],
      "links": [],
      "url": "https://mobsf.github.io/Mobile-Security-Framework-MobSF",
      "description": "Mobile app security framework.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "MobSF/Mobile-Security-Framework-MobSF"
      },
      "caps": [
        "mobile",
        "sast",
        "dast"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "mobile",
          "sast",
          "dast"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "npm-audit",
      "name": "npm audit",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://docs.npmjs.com/cli/v10/commands/npm-audit",
      "description": "Built-in npm dependency audit.",
      "access": "cli",
      "pricing": "free",
      "caps": [
        "deps",
        "sca"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "deps",
          "sca"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "nuclei",
      "name": "Nuclei",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/projectdiscovery/nuclei",
      "description": "Template-based vuln scanner.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "projectdiscovery/nuclei"
      },
      "caps": [
        "dast",
        "pentest"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "dast",
          "pentest"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "osv-scanner",
      "name": "OSV-Scanner",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/google/osv-scanner",
      "description": "Google's vuln database scanner.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "google/osv-scanner"
      },
      "caps": [
        "deps",
        "sca"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "deps",
          "sca"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "owasp-zap",
      "name": "OWASP ZAP",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://www.zaproxy.org",
      "description": "The Zed Attack Proxy — DAST.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "zaproxy/zaproxy"
      },
      "caps": [
        "dast",
        "proxy"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "dast"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "semgrep",
      "name": "Semgrep",
      "kind": "skill-source",
      "tags": [
        "security",
        "sast"
      ],
      "links": [],
      "url": "https://semgrep.dev",
      "description": "Static analysis rule engine.",
      "access": "oss",
      "pricing": "freemium",
      "github": {
        "repo": "semgrep/semgrep"
      },
      "kinds": [
        "security-tool",
        "skill-source"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "true",
        "topic": [
          "security",
          "sast"
        ],
        "host": [
          "generic"
        ]
      }
    },
    {
      "slug": "sonarqube",
      "name": "SonarQube",
      "kind": "security-tool",
      "tags": [
        "security",
        "sast"
      ],
      "links": [],
      "url": "https://www.sonarsource.com/products/sonarqube",
      "description": "Code quality + security analysis platform.",
      "access": "self-host",
      "pricing": "freemium",
      "caps": [
        "sast",
        "quality"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "sast"
        ],
        "oss": "false"
      }
    },
    {
      "slug": "strix",
      "name": "Strix",
      "kind": "security-tool",
      "tags": [
        "security",
        "pentest"
      ],
      "links": [],
      "url": "https://strix.ai",
      "description": "Autonomous AI penetration testing.",
      "access": "oss",
      "pricing": "freemium",
      "github": {
        "repo": "usestrix/strix"
      },
      "caps": [
        "pentest",
        "dast",
        "llm-sec"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "pentest",
          "dast",
          "llm-sec"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "trivy",
      "name": "Trivy",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://trivy.dev",
      "description": "Container + IaC + dependency scanner.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "aquasecurity/trivy"
      },
      "caps": [
        "container",
        "iac",
        "sca",
        "deps"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "container",
          "iac",
          "sca",
          "deps"
        ],
        "oss": "true"
      }
    },
    {
      "slug": "trufflehog",
      "name": "TruffleHog",
      "kind": "security-tool",
      "tags": [
        "security"
      ],
      "links": [],
      "url": "https://github.com/trufflesecurity/trufflehog",
      "description": "Find leaked credentials.",
      "access": "oss",
      "pricing": "free",
      "github": {
        "repo": "trufflesecurity/trufflehog"
      },
      "caps": [
        "secrets"
      ],
      "kinds": [
        "security-tool"
      ],
      "facets": {
        "scanType": [
          "secrets"
        ],
        "oss": "true"
      }
    }
  ]
}